🟠 High  |  Source: The Hacker News


A threat actor linked to East Asia has been conducting targeted cyberattacks against government organisations in the Middle East, deploying three previously unknown malware families: TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM notably abuses Telegram’s platform as a command-and-control (C2) channel, making malicious traffic harder to detect and block. The campaign was identified by Zscaler ThreatLabz and represents an active, ongoing threat to public sector targets.

Security Architect’s Take: Review egress controls to ensure outbound connections to Telegram’s API endpoints (api.telegram.org) from servers and workloads are whitelisted only where explicitly required — consider blocking or proxying them in government and sensitive enterprise environments. Additionally, ensure cloud-hosted workloads have behavioural monitoring in place to detect unusual use of legitimate messaging platforms as C2 channels.

Original advisory: TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments