DEV Community

Mark0
Mark0

Posted on

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

⚠️ Region Alert: UAE/Middle East

Cybersecurity researchers have identified a new campaign by an East Asian threat actor targeting government entities in the Middle East. The attack involves a multi-stage chain deploying previously unknown malware families—TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM specifically abuses the Telegram API for command-and-control (C2) communication, allowing it to blend into legitimate network traffic while using advanced obfuscation techniques like control flow flattening and mixed boolean arithmetic.

The malware leverages DLL sideloading and sophisticated anti-analysis measures, such as hypervisor detection via CPUID and environmental keying based on the target system's volume serial number. This ensures that the final C2 implant, BINDCLOAK, detonates only on the intended victim machines. Post-compromise activity suggests the operators remain active during specific UTC hours, focusing on system reconnaissance and payload delivery.


Read Full Article

Top comments (0)