HackMyIP
← Back to News
2026-07-27 The Hacker News

East Asia APT Abuses Telegram API for C2 in Middle East Attacks

APTMalwareThreat Intel

Zscaler ThreatLabz has uncovered a sophisticated cyber espionage campaign attributed to an East Asia-linked threat actor targeting government entities across the Middle East. Detected earlier this month, the operation deploys three previously undocumented malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—through a multi-stage attack chain designed to establish persistent access while evading detection. According to Sudeep Singh, senior manager of APT research at ThreatLabz, the campaign notably abuses the Telegram API for command-and-control (C2) communications, allowing malicious traffic to blend seamlessly with legitimate internet activity on monitored networks.

The attack initiates with an ISO file containing a legitimate executable ("RegSchdTask.exe") used to sideload a rogue DLL ("AsTaskSched.dll"), which activates TELESHIM—a 32-bit Windows backdoor. TELESHIM communicates over Telegram using two message types: control messages that register the infected host by transmitting its MAC address and executing received commands, and download-and-execute messages that fetch secondary payloads as scheduled tasks. Before initiating C2, the implant performs several anti-analysis checks, including hypervisor detection via CPUID and RAM speed verification using Windows Management Instrumentation (WMI). Organizations investigating suspicious outbound traffic patterns can use a port scanner to identify unusual connections or a DNS leak test to detect anomalous resolver behavior that may indicate compromised endpoints.

Following initial compromise, TELESHIM retrieves two payloads that trigger a second DLL side-loading chain comprising "GoProAlertService.exe" and "pthreadVC2.dll," the latter functioning as a reflective loader codenamed MIXEDKEY. MIXEDKEY decrypts and executes a file named "C99F29AC08454855B3D538960BB2F34F.PCPKEY," while both TELESHIM and MIXEDKEY employ heavy code obfuscation techniques, including string encryption, control flow flattening, mixed boolean arithmetic, and opaque predicates to frustrate reverse engineering efforts. The final payload is protected by two layers of XOR encryption, with the second layer using environmental keying—deriving a decryption key from the infected machine's volume serial number—to ensure detonation only on intended targets. Security teams investigating suspicious certificates or domains associated with the campaign, such as the C2 server "cert.hypersnet[.]com," can leverage a SSL/TLS checker or WHOIS lookup to gather infrastructure intelligence.

The attack sequence concludes with the deployment of BINDCLOAK, a 64-bit C++ C2 implant that establishes contact with an external server. ThreatLabz observed post-compromise activity between July 7 and July 9, 2026, including system, user, and network reconnaissance commands alongside the delivery of additional payloads. The C2 commands were executed only during a narrow four-hour daily window, suggesting a disciplined operator maintaining strict operational security. This campaign underscores how APT groups continue to weaponize trusted platforms like Telegram for covert communications and highlights the urgent need for defenders to monitor outbound API traffic to popular messaging services for signs of malicious abuse.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →