Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

TELESHIM Malware Abuses Telegram for Command-and-Control Communication in Middle East Government Attacks



A sophisticated malware campaign known as TELESHIM has been linked to attacks against government entities in the Middle East. This malicious activity leverages Telegram for command-and-control communication, utilizing an intricate multi-stage attack chain involving previously unreported malware families.

  • The TELESHIM malware campaign utilizes the Telegram API for command-and-control communication.
  • The malware employs an intricate multi-stage attack chain involving previously unreported malware families.
  • The attack sequence involves deploying a 32-bit Windows backdoor called TELESHIM, which leverages Telegram as its C2 channel.
  • The malware has been found to rely on heavy code obfuscation techniques to hinder reverse engineering efforts.
  • The TELESHIM malware uses XOR encryption with an environmental keying technique derived from the infected machine's volume serial number.
  • The attack sequence culminates in the deployment of a 64-bit C2 implant called BINDCLOAK, which was identified by ThreatLabz.
  • The malicious campaign has not been linked to any known threat actor or group as of yet.



  • Threat actors have been utilizing a sophisticated malware campaign, dubbed TELESHIM, which leverages the Telegram API for command-and-control (C2) communication to facilitate its operations. According to cybersecurity researchers at Zscaler ThreatLabz, this malicious activity has been identified in relation to government entities in the Middle East.

    The malware campaign employs an intricate multi-stage attack chain, involving the deployment of previously unreported malware families such as TELESHIM, MIXEDKEY, and BINDCLOAK. These malware families were discovered by Zscaler ThreatLabz during their detection of a malicious cyber activity earlier this month.

    The attack sequence begins with the distribution of an ISO file containing a legitimate executable named "RegSchdTask.exe." This ISO file serves as the initial vector for sideloading a rogue DLL called "AsTaskSched.dll," which subsequently installs a 32-bit Windows backdoor called TELESHIM. The TELESHIM malware leverages Telegram as its C2 communication channel to retrieve next-stage components.

    The attack sequence progresses with the deployment of two additional payloads, namely "GoProAlertService.exe" and "pthreadVC2.dll." These payloads participate in a second DLL sideloading chain, wherein "pthreadVC2.dll" functions as a reflective loader codenamed MIXEDKEY. The latter is employed to decrypt the contents of a file named "C99F29AC08454855B3D538960BB2F34F.PCPKEY" and execute it.

    The TELESHIM malware has been found to rely on heavy code obfuscation techniques, including string encryption, control flow flattening (CFF), mixed boolean arithmetic (MBA), and opaque predicates to hinder reverse engineering efforts. Furthermore, TELESHIM utilizes various methods to detect the presence of virtualization-based analysis environments, such as hypervisor detection using CPUID, RAM speed checks utilizing the Windows Management Instrumentation (WMI), and detection through other means.

    The C2 communications supported by TELESHIM comprise two primary types of messages: control messages and download and execute messages. Control messages are used to register infected hosts by sending their MAC addresses and executing received commands, as well as exfiltrating results back to the server in chunks if the output exceeds 1,000 bytes. On the other hand, download and execute messages are utilized to download and run secondary payloads as scheduled tasks.

    One notable aspect of the final payload is that it is locked behind two layers of XOR encryption, with the second layer utilizing an environmental keying technique derived from the infected machine's volume serial number. This feature ensures that the malware detonates only on intended targets.

    The attack sequence culminates in the deployment of BINDCLOAK, a 64-bit C2 implant written in C++. ThreatLabz identified post-compromise activity from the C2 operator, including system, user, and network reconnaissance commands as well as the delivery of next-stage payloads. The majority of this activity occurred between July 7th, 2026 and July 9th, 2026.

    ThreatLabz attributed the malicious campaign to a threat actor with ties to East Asia, who was believed to be operating from within that region based on their public IP address, system locale configured on their Windows server, geolocation of the IP address, and active operational hours. However, the campaign has not been linked to any known threat actor or group as of yet.

    The attack sequence's reliance on EDR evasion, blending in with legitimate internet traffic through abuse of trusted platforms, and utilization of code obfuscation techniques such as MBA and CFF to hinder reverse engineering reflect broader trends within the cybersecurity landscape.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/TELESHIM-Malware-Abuses-Telegram-for-Command-and-Control-Communication-in-Middle-East-Government-Attacks-ehn.shtml

  • https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html


  • Published: Mon Jul 27 04:49:25 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us