Skip to content
East Asian Threat Actor Targets Middle Eastern Governments with New Malware

East Asian Threat Actor Targets Middle Eastern Governments with New Malware

First seen 21 Jul 2026, 21:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 22, 2026 at 18:56 UTC

In July 2026, Zscaler ThreatLabz identified a targeted cyber campaign by an East Asian threat actor against government entities in the Middle East. The attack utilized a multi-stage chain to compromise systems, deploying previously undocumented malware tools including TELESHIM, MIXEDKEY, and BINDCLOAK. The initial infection vector involved an ISO file containing a legitimate ASUSTek executable that sideloaded a malicious DLL. TELESHIM, a 32-bit C++ Windows DLL, was used for command-and-control communication via the Telegram API, camouflaging its traffic. The malware employed advanced obfuscation techniques and encrypted strings to evade detection. The campaign's sophistication indicates a high level of planning and execution, with the malware designed to ensure only a single instance runs on infected machines. A follow-up post is expected to provide further analysis of the BINDCLOAK implant.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 50d ago How this analysis works

Timeline

2026-07-01
Malware campaign initiated
An East Asian threat actor began targeting government entities in the Middle East using sophisticated malware tools.
Zscaler
2026-07-21
Zscaler reports on malware tooling
Zscaler ThreatLabz published findings on newly identified malware including TELESHIM, MIXEDKEY, and BINDCLOAK.
Zscaler

More articles in this cluster (3)

Following this threat?

Track Bindcloak in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed