TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Cybersecurity researchers at Zscaler ThreatLabz have uncovered a malicious campaign targeting government entities in the Middle East, attributed to an East Asian…
Cybersecurity researchers at Zscaler ThreatLabz have uncovered a malicious campaign targeting government entities in the Middle East, attributed to an East Asian…
TELESHIM is a 32-bit Windows backdoor that abuses the Telegram API for command-and-control communication. It uses DLL side-loading via RegSchdTask.exe and AsTaskSched.dll,…
MIXEDKEY is a reflective loader used in the attack chain to decrypt and execute the final BINDCLOAK payload. It is delivered via…
Group-IB has uncovered a China-nexus cyber operation tracked as JadeProx, which has been targeting government, healthcare, and education organizations across Asia and…
TriBack Loader is a previously undocumented Windows loader used by the JadeProx operation. It employs DLL sideloading with four infection chains, using…
A modular .NET RAT delivered via DLL sideloading through a signed Ubisoft binary, part of the DlrtyGames campaign.
Its signed binary was used for DLL sideloading in the DlrtyGames campaign.
The China-aligned espionage group Mustang Panda is running two campaigns against Indian government and hydropower targets, deploying new malware and turning a…
SHARDLOADER is a malware loader used by Mustang Panda that sideloads a malicious DLL through legitimately signed binaries like Solid PDF Creator…