Researchers uncover TELESHIM malware using Telegram for command-and-control in attacks targeting Middle Eastern government entities.

A newly uncovered cyber espionage campaign targeting government entities in the Middle East is using Telegram as part of its command-and-control infrastructure, allowing malicious traffic to blend in with legitimate internet activity and making the attacks far more difficult to detect.
The campaign was discovered earlier this month by Zscaler ThreatLabz, which identified three previously undocumented malware families ; TELESHIM, MIXEDKEY, and BINDCLOAK. Working together, the malware creates a multi-stage infection chain designed to quietly establish and maintain access to compromised systems while avoiding security tools.
According to Sudeep Singh, Senior Manager of APT Research at Zscaler ThreatLabz, the attackers rely on several layers of malware, encrypted payloads, and DLL sideloading to move through a victim’s network without raising suspicion. One of the campaign’s more unusual features is its use of the Telegram API for command-and-control communications, allowing malicious traffic to appear similar to legitimate network activity.
The attack begins with a malicious ISO file containing a legitimate Windows executable named RegSchdTask.exe. When opened, the executable sideloads a rogue DLL called AsTaskSched.dll, which installs the TELESHIM backdoor.
Once active, TELESHIM contacts Telegram to receive instructions from the attackers and download additional malware components. The backdoor can also register newly infected devices by transmitting their MAC addresses before executing commands received from the operators. If command results exceed 1,000 bytes, the malware automatically divides the data into smaller pieces before sending it back.
The next phase introduces another DLL sideloading chain involving GoProAlertService.exe and a malicious pthreadVC2.dll file. Acting as a reflective loader known as MIXEDKEY, the DLL decrypts and launches an encrypted payload stored inside a file named C99F29AC08454855B3D538960BB2F34F.PCPKEY.
Researchers found the payload is protected by two layers of XOR encryption, making analysis significantly more difficult. The second layer uses a technique known as environmental keying, generating its decryption key from the infected computer’s volume serial number. As a result, the malware is designed to execute only on intended targets, frustrating automated analysis and many sandbox environments.
Both TELESHIM and MIXEDKEY also contain extensive anti-analysis protections. Researchers observed heavy use of string encryption, control flow flattening (CFF), mixed boolean arithmetic (MBA), and opaque predicates to obscure the malware’s functionality. TELESHIM further checks whether it is running inside a virtual machine by examining CPUID information and measuring RAM speed through Windows Management Instrumentation (WMI).
The final stage of the campaign deploys BINDCLOAK, a 64-bit command-and-control implant written in C++ that communicates with an external server identified as cert.hypersnet[.]com.
After compromising victim systems, the attackers carried out system, user, and network reconnaissance before deploying additional payloads. Zscaler observed this activity between July 7 and July 9, 2026, with command-and-control operations taking place exclusively between 4:00 a.m. and 12:00 p.m. UTC. Most of the activity occurred during a four-hour window between 7:00 a.m. and 11:00 a.m. UTC, suggesting a consistent operating schedule.
Although the campaign has not been linked to a known hacking group, researchers believe, with moderate-to-high confidence, that the operators are based in East Asia. That assessment is based on several indicators, including the public IP addresses used during the attacks, the Windows locale configured on the attackers’ infrastructure, IP geolocation data, and the hours during which the operators were active.
Researchers say the campaign reflects several broader trends emerging in advanced cyber espionage. Rather than relying solely on sophisticated exploits, attackers are increasingly hiding malicious communications inside trusted online services while using advanced obfuscation techniques to slow reverse engineering and evade endpoint detection and response (EDR) solutions.
As threat actors continue adopting legitimate platforms as part of their infrastructure, campaigns like this highlight how difficult modern cyber espionage has become to detect and why organizations can no longer rely on traditional indicators of compromise alone.
Related articles :
- React2Shell Exploited to Hijack NGINX Web Traffic
- Critical Nginx UI Flaw Enables Full Server Takeover
- Best Darknet Markets of 2026
Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.







