TELESHIM malware uses Telegram channels as C2 in Middle East government intrusions
Source headline: TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Intelligence Summary
Zscaler ThreatLabz reports a cyber campaign tied to East Asia targeting government organizations in the Middle East. The activity deploys previously unreported malware families named TELESHIM, MIXEDKEY, and BINDCLOAK. Investigators say the threat uses Telegram for command-and-control to coordinate infected systems. This increases the difficulty of detecting and blocking communications because traffic blends with legitimate messaging patterns. Government defenders should review for signs of these malware families and scrutinize outbound connections to Telegram-related infrastructure.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.