hacker-news · Crawled Jul 27, 2026

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

6 IoCs
Read original article ↗

AI Summary

A threat actor linked to East Asia has been conducting cyberattacks against government entities in the Middle East using a multi-stage infection chain. The campaign deploys novel malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—that leverage DLL sideloading and abuse Telegram's API for command-and-control (C2) communications to blend with legitimate traffic. TELESHIM uses heavy obfuscation and anti-analysis techniques, while the final payload employs environmental keying based on volume serial number for targeted execution. Post-compromise activity includes reconnaissance and payload delivery between July 7–9, 2026, primarily during morning UTC hours.

AI-extracted · verify before operational use

Indicators of Compromise 6 extracted

Type Value Detail
Domain cert[.]hypersnet[.]com Details →
Filename RegSchdTask.exe Details →
Filename AsTaskSched.dll Details →
Filename GoProAlertService.exe Details →
Filename pthreadVC2.dll Details →
MD5 c99f29ac08454855b3d538960bb2f34f Details →