hacker-news · Crawled Jul 27, 2026
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
6 IoCs
Read original article ↗
AI Summary
A threat actor linked to East Asia has been conducting cyberattacks against government entities in the Middle East using a multi-stage infection chain. The campaign deploys novel malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—that leverage DLL sideloading and abuse Telegram's API for command-and-control (C2) communications to blend with legitimate traffic. TELESHIM uses heavy obfuscation and anti-analysis techniques, while the final payload employs environmental keying based on volume serial number for targeted execution. Post-compromise activity includes reconnaissance and payload delivery between July 7–9, 2026, primarily during morning UTC hours.
AI-extracted · verify before operational use