TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Summary

Cybersecurity researchers have identified a new cyber campaign targeting Middle Eastern governments, attributed to a threat actor with links to East Asia. This campaign employs novel malware families named TELESHIM, MIXEDKEY, and BINDCLOAK, utilizing Telegram for command and control (C2) communication.

IFF Assessment

FOE

The discovery of new malware families and a sophisticated C2 infrastructure poses a direct threat to targeted organizations, indicating an active and evolving attack capability.

Defender Context

This highlights the need for enhanced network monitoring and threat intelligence to detect and defend against novel malware and sophisticated C2 techniques, particularly those leveraging legitimate services like Telegram. Organizations in the Middle East should be particularly vigilant regarding potential targeting by state-sponsored actors.

Read Full Story →