Back to News
Cybersecurity

New Malware Campaign TELESHIM Targets Middle Eastern Governments via Telegram

Cybersecurity researchers have identified a sophisticated campaign using Telegram for command and control, aimed at Middle Eastern government entities.

Recent findings from Zscaler ThreatLabz have uncovered a significant cyber operation attributed to a threat actor linked to East Asia, which specifically targets government institutions in the Middle East. The researchers reported the discovery of several new malware families, namely TELESHIM, MIXEDKEY, and BINDCLOAK, that are being employed in these attacks. This campaign, detected earlier this month, underscores the evolving tactics used by cybercriminals to exploit communication platforms for malicious purposes.

For businesses, especially those operating within or in partnership with governmental entities in the Middle East, this development highlights the urgent need for enhanced cybersecurity measures. The use of platforms like Telegram for command and control (C2) mechanisms represents a shift in threat actor strategies, necessitating a reevaluation of existing security protocols, including advanced monitoring and threat intelligence capabilities. Understanding these emerging threats is crucial, as they not only pose risks to sensitive governmental data but also have broader implications for national security and geopolitical stability. The situation calls for proactive engagement in cybersecurity best practices to mitigate potential risks associated with novel malware and exploitation techniques.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/07/teleshim-abuses-telegram-for-c2-in.html)*