As cited
Copy frozen at (site build).
threat intel
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Zscaler ThreatLabz identified a campaign from an East Asia-linked threat actor deploying three previously unreported malware families, named TELESHIM, MIXEDKEY, and BINDCLOAK, against Middle Eastern government entities. The intrusions leverage Telegram as a command and control channel. The activity was detected in early 2025.
Why it matters: Government security teams in the Middle East and defense contractors supporting them face targeted intrusions using novel malware; practitioners should monitor for these families and block known Telegram-based command channels.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Zscaler ThreatLabz identified a campaign in mid-July 2026 deploying three previously unreported malware families (TELESHIM, MIXEDKEY, and BINDCLOAK) against Middle Eastern government entities. The threat actor, linked to East Asia, leverages Telegram for command and control communications.
Why it matters: Middle Eastern government networks face direct targeting; practitioners managing defenses in this region should review detection signatures for these malware families and monitor for Telegram-based C2 channels.
- Source published
- First seen by Cybersecurity Tracker