Zscaler East Asian Threat Actor Targets Middle Eastern Governments with New Malware
Article Content
- •A targeted attack by an East Asian threat actor is aimed at Middle Eastern government entities.
- •The campaign employs multi-stage malware including TELESHIM, MIXEDKEY, and BINDCLOAK.
- •TELESHIM uses the Telegram API for C2 communication, blending in with legitimate traffic.
In July 2026, Zscaler ThreatLabz identified a targeted cyber campaign by an East Asian threat actor against government entities in the Middle East. The attack utilized a multi-stage chain to compromise systems, deploying previously undocumented malware tools including TELESHIM, MIXEDKEY, and BINDCLOAK. The initial infection vector involved an ISO file containing a legitimate ASUSTek executable that sideloaded a malicious DLL. TELESHIM, a 32-bit C++ Windows DLL, was used for command-and-control communication via the Telegram API, camouflaging its traffic. The malware employed advanced obfuscation techniques and encrypted strings to evade detection. The campaign's sophistication indicates a high level of planning and execution, with the malware designed to ensure only a single instance runs on infected machines. A follow-up post is expected to provide further analysis of the BINDCLOAK implant.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Bindcloak in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Manipulation Campaigns Exploit Indirect Prompt Injection Techniques Zscaler's ThreatLabz identified two campaigns using indirect prompt injection (IPI) to manipulate AI agents into executing fraudulent actions. The first campaign involves a payment scam disguised as API documentation, tricking AI agents into sending funds to attacker-controlled accounts. The second campaign employs a…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…