CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3240

As cited

Copy frozen at (site build).

threat intel

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Zscaler ThreatLabz identified a campaign from an East Asia-linked threat actor deploying three previously unreported malware families, named TELESHIM, MIXEDKEY, and BINDCLOAK, against Middle Eastern government entities. The intrusions leverage Telegram as a command and control channel. The activity was detected in early 2025.

Why it matters: Government security teams in the Middle East and defense contractors supporting them face targeted intrusions using novel malware; practitioners should monitor for these families and block known Telegram-based command channels.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Zscaler ThreatLabz identified a campaign in mid-July 2026 deploying three previously unreported malware families (TELESHIM, MIXEDKEY, and BINDCLOAK) against Middle Eastern government entities. The threat actor, linked to East Asia, leverages Telegram for command and control communications.

Why it matters: Middle Eastern government networks face direct targeting; practitioners managing defenses in this region should review detection signatures for these malware families and monitor for Telegram-based C2 channels.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary