TELESHIM and Telegram: abusing a trusted platform in attacks on Middle Eastern government entities

Colleagues, I’d like to draw your attention to a cybersecurity development.
I noticed a campaign targeting government organizations in the Middle East. Researchers attribute it to an East Asian threat actor.
The attack deployed new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.
Telegram was used as a C2 channel to make traffic appear legitimate.
DLL sideloading, code obfuscation, and virtual environment checks were also used.
Why it matters: threat actors are increasingly hiding behind trusted services and making analysis more difficult.
In your view, which defensive measures are most effective against campaigns like this?
#cybersecurity #threatintelligence #malware #infosec


Latest comments
No comments yet.