TELESHIM Uses Telegram C2 Against Middle East Governments
Zscaler ThreatLabz flags three new malware families targeting Middle East government entities. The C2 channel: Telegram. Attribution: East Asia-linked.
Confirmed. Zscaler ThreatLabz disclosed the campaign on July 27, 2026: an East Asia-linked threat actor has compromised government entities across the Middle East, deploying three previously undocumented malware families — TELESHIM, MIXEDKEY, and BINDCLOAK — with Telegram as the C2 channel.
Campaign detection timeline: earlier in July 2026. Specific government targets: unconfirmed. State attribution beyond “East Asia-linked”: unconfirmed — treat accordingly.
The toolset
Three new families. All previously unknown.
TELESHIM is the primary implant and the one that gives the campaign its name. It uses Telegram as its command-and-control channel, routing attacker instructions through the messaging platform rather than a dedicated C2 server or attacker-controlled domain.
MIXEDKEY and BINDCLOAK are the supporting components. Specific capabilities of each: not detailed in the initial disclosure. Function in the attack chain: pending the full ThreatLabz report.
The Telegram C2 pattern is an established evasion technique. Telegram traffic from an enterprise endpoint doesn’t trigger the same network-layer signature matching as outbound connections to attacker-controlled IPs or known C2 infrastructure. Blocking it cleanly requires application-layer controls. Most organizations don’t have those in place specifically for Telegram.
Current status
- Government entities in the Middle East: compromised. Confirmed per ThreatLabz research.
- Specific countries or agencies targeted: unconfirmed.
- Ongoing activity as of publication: treat as active until contradicted.
- Full IOCs from ThreatLabz: pending the primary research publication. Current coverage is via secondary reporting.
Recommended action
For organizations with Middle East government exposure — contractors, suppliers, regional offices:
- Review outbound Telegram API connections from production systems. Flag anything that doesn’t map to a known workflow.
- Check endpoint logs from the past 30 days for staging indicators — dropped executables, new scheduled tasks, unexplained persistence entries.
- Pull full IOCs from the ThreatLabz primary report when it publishes. The initial secondary summary does not include indicators.
East Asia-linked activity against government targets has been consistently elevated this month. For related campaign context: JadeProx deploying TriBack Loader against government and healthcare targets and ToddyCat’s OAuth and Gmail-based C2 infrastructure.
For broader campaign tracking, see the Threat Intel & Field Notes hub.
Found this useful? Share it.


