New TELESHIM campaign abuses Telegram for C2
🛡️ Zscaler ThreatLabz has detected an East Asia–linked campaign targeting Middle Eastern government entities that deploys three previously unreported malware families: TELESHIM, MIXEDKEY, and BINDCLOAK. The attack begins with an ISO that sideloads a rogue DLL to run a 32‑bit backdoor (TELESHIM) which uses the Telegram API for command-and-control, then stages additional payloads via DLL side‑loading and a reflective loader (MIXEDKEY). TELESHIM and MIXEDKEY employ heavy obfuscation and anti-analysis checks, while the final 64‑bit implant BINDCLOAK communicates with an external C2 server; observed activity occurred between July 7–9, 2026.
