Cybersecurity researchers have uncovered a new campaign where an East‑Asia‑linked threat actor uses Telegram as a command‑and‑control (C2) channel to target government entities across the Middle East. Zscaler ThreatLabz detected the operation earlier this month, highlighting three previously unknown malware families.

Key Takeaways

  • New malware families—TELESHIM, MIXEDKEY, and BINDCLOAK—have been deployed.
  • The threat actor leveraged Telegram’s encrypted messaging as a stealthy C2 platform.
  • Zscaler ThreatLabz identified the campaign in the first week of the month.

Zscaler ThreatLabz reports that an East‑Asian‑affiliated group has turned Telegram into a command‑and‑control hub, striking multiple Middle‑East government agencies. The operation introduced three never‑seen‑before malware families: TELESHIM, MIXEDKEY and BINDCLOAK, each designed to evade traditional detection.

These payloads feature encrypted beaconing, side‑loaded loaders and self‑updating mechanisms, making remediation difficult. Telegram’s end‑to‑end encryption and global reach allowed rapid command dissemination and data exfiltration without raising typical network alarms.

Historical Background

Since 2020, threat actors have increasingly adopted mainstream messaging apps for C2 because they provide free, encrypted, and widely‑available channels. Earlier state‑backed campaigns used WhatsApp or Signal; the shift to Telegram marks a more sophisticated, harder‑to‑track approach.

Why This Matters

BozokMedia analysis shows that the shift to mainstream messaging apps for C2 indicates a new phase in cyber‑espionage, where detection becomes harder for traditional network security tools. Governments must reassess their monitoring strategies to include encrypted messaging traffic.

“Using Telegram as a C2 server is a game‑changer; it obscures attacker activity while speeding up command delivery,” says cyber‑security expert Dr. Lina Patel.
Did You Know?: Telegram, launched in 2013, became one of the world’s most popular encrypted messaging apps in 2022‑2023, making it an attractive vector for malicious actors.

Frequently Asked Questions

Q1: Is this attack limited to the Middle East?

A: While current victims are predominantly Middle‑East government bodies, the global nature of Telegram means other regions could be targeted next.

Q2: How can organizations defend against Telegram‑based C2?

A: Deploy encrypted‑traffic analytics, enforce multi‑factor authentication, and use advanced endpoint detection and response solutions.