Find notable cyber news and cases, enriched with sources, timelines, and signals.

TELESHIM, MIXEDKEY, and BINDCLOAK malware activity targeting Middle East government entities

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

A new malware operation against government entities in the Middle East deployed the previously unreported families TELESHIM, MIXEDKEY, and BINDCLOAK, expanding the reach of a multi-stage intrusion chain. TELESHIM used the Telegram API for C2 and blended into legitimate traffic, while ISO-based DLL sideloading delivered the payloads. MIXEDKEY functioned as a reflective loader and BINDCLOAK served as the final 64-bit C2 implant contacting cert.hypersnet[.]com. Post-compromise activity was observed between July 7, 2026 and July 9, 2026, including reconnaissance and delivery of next-stage payloads.

Related Happenings

East Asia-linked campaign targeting Middle East government entities

Campaign
H score32 First: 27.07.2026 11:48 Last: 27.07.2026 11:48 Sources 1

How related: Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.

About this happening: A multi-stage campaign linked to East Asia is targeting government entities in the Middle East, using malware deployment and trusted-platform abuse to maintain access....

TELEPUZ modular malware spread via ClickFix lures

Malware Activity
H score29 First: 16.07.2026 15:50 Last: 16.07.2026 15:50 Sources 1

About this happening: The TELEPUZ malware family is actively spreading through ClickFix lures, raising the risk of credential theft and remote command execution on infected systems. The...

Millenium RAT Windows malware activity and native C++ rewrite

Malware Activity
H score62 First: 29.06.2026 17:30 Last: 29.06.2026 17:30 Sources 1

About this happening: The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...

TinyRCT backdoor used in CL-STA-1062 Southeast Asia intrusions

Malware Activity
H score15 First: 26.06.2026 19:21 Last: 26.06.2026 19:21 Sources 1

About this happening: The newly documented TinyRCT backdoor gives CL-STA-1062 a custom remote-access payload for government and critical-infrastructure targets in Southeast Asia, expanding...

RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations

Malware Activity
H score28 First: 25.05.2026 12:32 Last: 25.05.2026 12:32 Sources 1

About this happening: The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...

Timeline

  1. 27.07.2026 11:48 2 articles · 2h ago

    Zscaler flags TELESHIM, MIXEDKEY, and BINDCLOAK campaign against Middle East governments

    Initial Disclosure

    Zscaler ThreatLabz identified a multi-stage intrusion campaign targeting government entities in the Middle East that deployed the previously unreported malware families TELESHIM, MIXEDKEY, and BINDCLOAK, used ISO-based DLL sideloading and the Telegram API for C2, and was assessed with moderate-to-high confidence as originating from East Asia. The intrusion chain started with RegSchdTask.exe sideloading AsTaskSched.dll, used pthreadVC2.dll as the MIXEDKEY reflective loader to decrypt C99F29AC08454855B3D538960BB2F34F.PCPKEY, and culminated in BINDCLOAK contacting cert.hypersnet[.]com; ThreatLabz also observed post-compromise reconnaissance and next-stage payload delivery between July 7, 2026 and July 9, 2026.

    Show sources