East Asian Threat Actor Targets Middle Eastern Governments with New Malware

East Asian Threat Actor Targets Middle Eastern Governments with New Malware

First seen 21 Jul 2026, 21:55 UTC Zscaler 96% similarity 72.5

Article Content

Browse articles
ThreatCluster

In July 2026, Zscaler ThreatLabz identified a targeted cyber campaign by an East Asian threat actor against government entities in the Middle East. The attack utilized a multi-stage chain to compromise systems, deploying previously undocumented malware tools including TELESHIM, MIXEDKEY, and BINDCLOAK. The initial infection vector involved an ISO file containing a legitimate ASUSTek executable that sideloaded a malicious DLL. TELESHIM, a 32-bit C++ Windows DLL, was used for command-and-control communication via the Telegram API, camouflaging its traffic. The malware employed advanced obfuscation techniques and encrypted strings to evade detection. The campaign's sophistication indicates a high level of planning and execution, with the malware designed to ensure only a single instance runs on infected machines. A follow-up post is expected to provide further analysis of the BINDCLOAK implant.

Key Points: • A targeted attack by an East Asian threat actor is aimed at Middle Eastern government entities. • The campaign employs multi-stage malware including TELESHIM, MIXEDKEY, and BINDCLOAK. • TELESHIM uses the Telegram API for C2 communication, blending in with legitimate traffic.

ThreatCluster AI

Timeline

2026-07-01
Malware campaign initiated
An East Asian threat actor began targeting government entities in the Middle East using sophisticated malware tools.
Zscaler
2026-07-21
Zscaler reports on malware tooling
Zscaler ThreatLabz published findings on newly identified malware including TELESHIM, MIXEDKEY, and BINDCLOAK.
Zscaler

Community

Browse all →