Skip to content
feed: live
>_ 0dayNews
threat intel
● Breaking

TELESHIM Uses Telegram C2 Against Middle East Governments

Zscaler ThreatLabz flags three new malware families targeting Middle East government entities. The C2 channel: Telegram. Attribution: East Asia-linked.

TELESHIM Uses Telegram C2 Against Middle East Governments
Image: 0dayNews / 0dayNews Editorial · All rights reserved
airgap airgap · Published · 2 min read

Confirmed. Zscaler ThreatLabz disclosed the campaign on July 27, 2026: an East Asia-linked threat actor has compromised government entities across the Middle East, deploying three previously undocumented malware families — TELESHIM, MIXEDKEY, and BINDCLOAK — with Telegram as the C2 channel.

Campaign detection timeline: earlier in July 2026. Specific government targets: unconfirmed. State attribution beyond “East Asia-linked”: unconfirmed — treat accordingly.

The toolset

Three new families. All previously unknown.

TELESHIM is the primary implant and the one that gives the campaign its name. It uses Telegram as its command-and-control channel, routing attacker instructions through the messaging platform rather than a dedicated C2 server or attacker-controlled domain.

MIXEDKEY and BINDCLOAK are the supporting components. Specific capabilities of each: not detailed in the initial disclosure. Function in the attack chain: pending the full ThreatLabz report.

The Telegram C2 pattern is an established evasion technique. Telegram traffic from an enterprise endpoint doesn’t trigger the same network-layer signature matching as outbound connections to attacker-controlled IPs or known C2 infrastructure. Blocking it cleanly requires application-layer controls. Most organizations don’t have those in place specifically for Telegram.

Current status

  • Government entities in the Middle East: compromised. Confirmed per ThreatLabz research.
  • Specific countries or agencies targeted: unconfirmed.
  • Ongoing activity as of publication: treat as active until contradicted.
  • Full IOCs from ThreatLabz: pending the primary research publication. Current coverage is via secondary reporting.

For organizations with Middle East government exposure — contractors, suppliers, regional offices:

  1. Review outbound Telegram API connections from production systems. Flag anything that doesn’t map to a known workflow.
  2. Check endpoint logs from the past 30 days for staging indicators — dropped executables, new scheduled tasks, unexplained persistence entries.
  3. Pull full IOCs from the ThreatLabz primary report when it publishes. The initial secondary summary does not include indicators.

East Asia-linked activity against government targets has been consistently elevated this month. For related campaign context: JadeProx deploying TriBack Loader against government and healthcare targets and ToddyCat’s OAuth and Gmail-based C2 infrastructure.

For broader campaign tracking, see the Threat Intel & Field Notes hub.


Source: The Hacker News / Zscaler ThreatLabz, July 27, 2026

Found this useful? Share it.