TELESHIM, MIXEDKEY, and BINDCLOAK malware activity targeting Middle East government entities
Malware Activity
Summary
Hide ▲
Show ▼
A new malware operation against government entities in the Middle East deployed the previously unreported families TELESHIM, MIXEDKEY, and BINDCLOAK, expanding the reach of a multi-stage intrusion chain. TELESHIM used the Telegram API for C2 and blended into legitimate traffic, while ISO-based DLL sideloading delivered the payloads. MIXEDKEY functioned as a reflective loader and BINDCLOAK served as the final 64-bit C2 implant contacting cert.hypersnet[.]com. Post-compromise activity was observed between July 7, 2026 and July 9, 2026, including reconnaissance and delivery of next-stage payloads.
Related Happenings
East Asia-linked campaign targeting Middle East government entities
Campaign
H score32
First: 27.07.2026 11:48
Last: 27.07.2026 11:48
Sources 1
How related:
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.
About this happening:
A multi-stage campaign linked to East Asia is targeting government entities in the Middle East, using malware deployment and trusted-platform abuse to maintain access....
East Asia-linked campaign targeting Middle East government entities
CampaignHow related: Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.
About this happening: A multi-stage campaign linked to East Asia is targeting government entities in the Middle East, using malware deployment and trusted-platform abuse to maintain access....
TELEPUZ modular malware spread via ClickFix lures
Malware Activity
H score29
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The TELEPUZ malware family is actively spreading through ClickFix lures, raising the risk of credential theft and remote command execution on infected systems. The...
TELEPUZ modular malware spread via ClickFix lures
Malware ActivityAbout this happening: The TELEPUZ malware family is actively spreading through ClickFix lures, raising the risk of credential theft and remote command execution on infected systems. The...
Millenium RAT Windows malware activity and native C++ rewrite
Malware Activity
H score62
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...
Millenium RAT Windows malware activity and native C++ rewrite
Malware ActivityAbout this happening: The Millenium RAT malware activity is spreading across Windows systems, with 60,000+ infections in 160+ countries and a newer native C++ build that helps it ev...
TinyRCT backdoor used in CL-STA-1062 Southeast Asia intrusions
Malware Activity
H score15
First: 26.06.2026 19:21
Last: 26.06.2026 19:21
Sources 1
About this happening:
The newly documented TinyRCT backdoor gives CL-STA-1062 a custom remote-access payload for government and critical-infrastructure targets in Southeast Asia, expanding...
TinyRCT backdoor used in CL-STA-1062 Southeast Asia intrusions
Malware ActivityAbout this happening: The newly documented TinyRCT backdoor gives CL-STA-1062 a custom remote-access payload for government and critical-infrastructure targets in Southeast Asia, expanding...
RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations
Malware Activity
H score28
First: 25.05.2026 12:32
Last: 25.05.2026 12:32
Sources 1
About this happening:
The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...
RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations
Malware ActivityAbout this happening: The RemotePE malware has been tied to Lazarus Group activity against financial and cryptocurrency organizations, raising the risk of stealthy long-term access and late...
Timeline
-
27.07.2026 11:48 2 articles · 2h ago
Zscaler flags TELESHIM, MIXEDKEY, and BINDCLOAK campaign against Middle East governments
Initial DisclosureZscaler ThreatLabz identified a multi-stage intrusion campaign targeting government entities in the Middle East that deployed the previously unreported malware families TELESHIM, MIXEDKEY, and BINDCLOAK, used ISO-based DLL sideloading and the Telegram API for C2, and was assessed with moderate-to-high confidence as originating from East Asia. The intrusion chain started with RegSchdTask.exe sideloading AsTaskSched.dll, used pthreadVC2.dll as the MIXEDKEY reflective loader to decrypt C99F29AC08454855B3D538960BB2F34F.PCPKEY, and culminated in BINDCLOAK contacting cert.hypersnet[.]com; ThreatLabz also observed post-compromise reconnaissance and next-stage payload delivery between July 7, 2026 and July 9, 2026.
Show sources
- TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments — thehackernews.com — 27.07.2026 11:48
- TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments — thehackernews.com — 27.07.2026 11:48