Zscaler
East Asian Threat Actor Targets Middle Eastern Governments with New Malware
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In July 2026, Zscaler ThreatLabz identified a targeted cyber campaign by an East Asian threat actor against government entities in the Middle East. The attack utilized a multi-stage chain to compromise systems, deploying previously undocumented malware tools including TELESHIM, MIXEDKEY, and BINDCLOAK. The initial infection vector involved an ISO file containing a legitimate ASUSTek executable that sideloaded a malicious DLL. TELESHIM, a 32-bit C++ Windows DLL, was used for command-and-control communication via the Telegram API, camouflaging its traffic. The malware employed advanced obfuscation techniques and encrypted strings to evade detection. The campaign's sophistication indicates a high level of planning and execution, with the malware designed to ensure only a single instance runs on infected machines. A follow-up post is expected to provide further analysis of the BINDCLOAK implant.
Key Points: • A targeted attack by an East Asian threat actor is aimed at Middle Eastern government entities. • The campaign employs multi-stage malware including TELESHIM, MIXEDKEY, and BINDCLOAK. • TELESHIM uses the Telegram API for C2 communication, blending in with legitimate traffic.