TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities via DLL Sideloading and Telegram C2 — Threadlinqs Intelligence
As of 2026-07-28, TELESHIM/MIXEDKEY/BINDCLOAK: Unattributed East Asian Threat Actor Targets Middle East Government Entities via DLL Sideloading and Telegram C2 is a high-severity malware threat attributed to Unattributed East Asian Threat Actor (TELESHIM (Unknown (East Asia, moderate-to-high confidence)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 42 indicators of compromise.
Threat ID: TL-2026-1562 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-28 · revalidated 1× · latest source
Attribution: Unattributed East Asian Threat Actor (TELESHIM · Unknown (East Asia, moderate-to-high confidence) · ESPIONAGE
Zscaler ThreatLabz documents a targeted intrusion campaign against Middle East government entities by an unattributed, moderate-to-high confidence East Asian threat actor. The campaign chains a
In early-to-mid July 2026, Zscaler ThreatLabz identified a targeted intrusion campaign against government entities in the Middle East, attributed with moderate-to-high confidence to an East Asian threat actor based on public IP geolocation, system locale configuration, and operational hours (4 AM-12 PM UTC, concentrated 7-11 AM UTC). The actor is not attributed to any known APT group at time of publication.
Initial access is achieved via spear-phishing with an ISO attachment themed as a 'Cooperation protocol for the exploration of petroleum and gas' (English), a geopolitically-tailored lure consistent with government/energy-sector targeting in the Middle East. The ISO contains a legitimate ASUSTek binary (RegSchdTask.exe) alongside a malicious sideloaded DLL (AsTaskSched.dll), which is the TELESHIM first-stage backdoor.
TELESHIM is a 32-bit C++ DLL compiled in July 2026 for this campaign (with earlier variants dating to 2025), protected by control-flow flattening, mixed boolean arithmetic (MBA), and opaque predicates. It encrypts strings using two separate schemes: per-function XOR keys, and Base64 encoding layered with a 44-byte rolling XOR key. TELESHIM installs a 7-byte inline hook at offset 0x1394 in the host executable, stages follow-on payloads to C:\programdata\shimgen_Data\, fingerprints the host via MAC address (GetAdaptersInfo), and communicates over a Telegram bot API C2 channel (api.telegram.org/bot/getUpdates) using a spoofed legacy Safari/WebKit User-Agent string. It establishes persistence via a scheduled task named 'shimgen' that re-executes every 6 minutes from C:\programdata\shimgen_Data\shimgen.exe, and uses the mutex '_----WebKitFormBoundary7MA4YWxkTrZu0g' to prevent multiple concurrent instances. Telegram C2 traffic is validated by chat-ID checking to prevent channel hijacking, and supports both direct control commands and download-and-execute operations.
A secondary DLL sideloading chain delivers MIXEDKEY, a 64-bit reflective loader, via a renamed GoPro-signed binary sideloading pthreadVC2.dll (accompanied by legitimate MSVCP120.dll/MSVCR120.dll runtime libraries), persisted through a second scheduled task named 'Feedback' running every 10 minutes. MIXEDKEY is heavily obfuscated (~1,000 MBA instructions per byte computed) and uses environmental keying tied to the infected host's volume serial number: it queries the 4-byte serial via GetVolumeInformationA, repeats it 5 times to derive a 20-byte rolling XOR key, then uses the first 311 bytes of an encrypted payload file as a second rolling XOR key to decrypt and reflectively load the next stage in memory, stripping the embedded 'MZ' PE signature and a size-prefix header in the process. The final payload is stored at C:\ProgramData\Crypto\DSS\C99F29AC08454855B3D538960BB2F34F.PCPKEY.
BINDCLOAK is the final-stage 64-bit C2 implant reflectively loaded by MIXEDKEY, communicating with the hardcoded domain cert.hypersnet[.]com; Zscaler deferred detailed protocol/capability analysis to a Part 2 report not yet published at time of writing.
The malware chain incorporates multiple anti-analysis and anti-sandbox techniques: a CPUID-based hypervisor detection check (EAX=1, bit 31 of ECX), an I/O-stall routine performing 1,000 iterations of ~1MB read/write against a temp file (%TEMP%\CVR9EEA.tmp) to detect accelerated sandbox clocks, and a WMI-based memory-speed check ('wmic memorychip get speed') that terminates execution if the value returns 0 or undefined (a common indicator of virtualized/sandboxed memory).
Post-compromise, the operator issued interactive reconnaissance commands consistent with hands-on-keyboard activity during observed operational hours of July 7-9, 2026: local account enumeration (net user), process listing (tasklist), hostname collection, network configuration and DNS cache dumps (ipconfig /all, ipconfig /displaydns), active connection enumeration (netstat -ano), directory listings of C:\Users and C:\ProgramData subdirectories, scheduled tas
Target sectors: government administration
Target regions: Middle East
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 42 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1569, T1053, T1053, T1574, T1574, T1036, T1027, T1497, T1497