⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

July 27, 2026

Cybersecurity researchers at Zscaler ThreatLabz have uncovered a malicious campaign targeting government entities in the Middle East, attributed to an East Asian threat actor. The attacks deploy previously unreported malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.

The attack chain begins with an ISO file containing a legitimate executable (RegSchdTask.exe) used to sideload a rogue DLL (AsTaskSched.dll). This DLL is a 32-bit Windows backdoor called TELESHIM, which abuses the Telegram API for command-and-control (C2) communication to blend in with legitimate traffic. TELESHIM retrieves next-stage components, including two payloads that trigger a second DLL side-loading chain using GoProAlertService.exe and pthreadVC2.dll. The latter acts as a reflective loader (MIXEDKEY) to decrypt and execute the final payload.

Both TELESHIM and MIXEDKEY employ heavy code obfuscation techniques such as string encryption, control flow flattening (CFF), mixed boolean arithmetic (MBA), and opaque predicates. TELESHIM also detects virtualization environments using CPUID hypervisor detection and RAM speed checks via WMI. Its C2 communications support control messages (for host registration and command execution) and download-and-execute messages (for secondary payloads).

The final payload, BINDCLOAK, is a 64-bit C++ implant that contacts an external server (cert.hypersnet[.]com). Post-compromise activity included system, user, and network reconnaissance, with commands executed between 4 a.m. and 12 p.m. UTC, primarily from 7 a.m. to 11 a.m. UTC. The threat actor’s public IP, system locale, and operational hours suggest an East Asian origin, though no known group has been attributed.

CVEs: CVE-2026-50522

Attack groups: East Asian Threat Actor

Malware: TELESHIM, MIXEDKEY, BINDCLOAK

Companies: Zscaler

Products: Telegram