DEV Community

Mark0
Mark0

Posted on

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

⚠️ Region Alert: UAE/Middle East

Cybersecurity researchers at Zscaler ThreatLabz have identified a new cyber campaign targeting government entities in the Middle East, attributed to a threat actor with ties to East Asia. The attack chain involves the deployment of three previously unknown malware families: TELESHIM, MIXEDKEY, and BINDCLOAK. Notably, the campaign leverages the Telegram API for command-and-control (C2) communication to mask its malicious traffic within legitimate internet data.

The infection process utilizes multi-stage DLL side-loading and advanced obfuscation techniques, including control flow flattening and mixed boolean arithmetic, to hinder analysis. To ensure precision, the final BINDCLOAK payload uses environmental keying based on the victim's volume serial number, ensuring the malware only executes on the intended target. While the actor remains unattributed, their operational hours and system locale suggest a base of operations in East Asia.


Read Full Article

Top comments (0)