Find notable cyber news and cases, enriched with sources, timelines, and signals.

East Asia-linked campaign targeting Middle East government entities

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

A multi-stage campaign linked to East Asia is targeting government entities in the Middle East, using malware deployment and trusted-platform abuse to maintain access. The operation matters because it combines TELESHIM, MIXEDKEY, and BINDCLOAK with Telegram API command-and-control and obfuscation to blend into normal traffic. Activity was observed July 7-9, 2026, with post-compromise reconnaissance and payload delivery recorded on infected systems.

Related Happenings

TELESHIM, MIXEDKEY, and BINDCLOAK malware activity targeting Middle East government entities

Malware Activity
H score22 First: 27.07.2026 11:48 Last: 27.07.2026 11:48 Sources 1

How related: The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz.

About this happening: A new malware operation against government entities in the Middle East deployed the previously unreported families TELESHIM, MIXEDKEY, and BINDCLOAK, expanding...

Iranian MOIS Telegram malware campaign targeting opposition groups

Campaign
H score32 First: 23.03.2026 11:45 Last: 23.03.2026 11:45 Sources 1

About this happening: The FBI warned that Iranian MOIS-linked hackers are using Telegram C2 and social engineering to deliver Windows malware against journalists, dissidents, and ot...

Dust Specter Iraq Foreign Affairs AI impersonation campaign

Campaign
H score33 First: 03.03.2026 12:30 Last: 03.03.2026 12:30 Sources 1

About this happening: Dust Specter targeted Iraqi government officials in a January 2026 campaign that used impersonation, AI tools, and compromised infrastructure to deliver malici...

Anonymous Fénix DDoS and volunteer-recruitment campaign

Campaign
H score29 First: 23.02.2026 23:59 Last: 23.02.2026 23:59 Sources 1

About this happening: Anonymous Fénix escalated its DDoS campaign by recruiting volunteers, increasing disruption risk for government and public-institution domains across Spain and par...

NoName057(16) disruptive DDoS campaign against UK and European organisations

Campaign
H score30 First: 19.01.2026 17:30 Last: 19.01.2026 17:30 Sources 1

About this happening: NoName057(16) and other Russian-aligned hacktivist groups are sustaining a DoS/DDoS disruption campaign against UK organisations, raising the risk of website outages a...

Timeline

  1. 27.07.2026 11:48 2 articles · 2h ago

    East Asia-linked campaign targets Middle East government entities

    Initial Disclosure

    Zscaler ThreatLabz identified a multi-stage intrusion campaign targeting government entities in the Middle East and assessed with moderate-to-high confidence that it originated from East Asia. The intrusion chain deployed previously unreported malware families TELESHIM, MIXEDKEY, and BINDCLOAK, used ISO-based DLL sideloading, abused the Telegram API for command-and-control, relied on heavy code obfuscation, and used environmental keying so the final payload would detonate only on intended targets. ThreatLabz said it detected the campaign earlier this month and later observed post-compromise reconnaissance and next-stage payload delivery on infected systems between July 7, 2026 and July 9, 2026.

    Show sources