The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity firm Zscaler ThreatLabz has identified a cyber espionage campaign targeting government entities in the Middle East, which it attributes with moderate-to-high confidence to a threat actor based in East Asia.
- The attacks use a multi-stage chain deploying three previously unreported malware families — TELESHIM, MIXEDKEY, and BINDCLOAK — with TELESHIM abusing Telegram for command-and-control to blend in with legitimate traffic.
- The malware employs heavy obfuscation, virtualization detection, and environmental keying to ensure it only runs on intended targets.
- Post-compromise activity, including reconnaissance and payload delivery, was observed between July 7 and July 9, 2026, though the campaign has not yet been tied to any known group.
What to watch next
- Whether Zscaler or other firms attribute the campaign to a specific known threat actor or group
- Any additional Middle East government victims or sectors revealed as the investigation continues
- Further use of trusted platforms like Telegram for command-and-control in future campaigns
Coverage1
1 report
English national1
All filed from India
Named Iraq · Oman · Saudi Arabia · United Arab Emirates · Kuwait · Bahrain · Middle East · Windows · BINDCLOAK · East Asia · MIXEDKEY · Sudeep Singh · Telegram · TELESHIM · Zscaler ThreatLabz
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
