FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Telegram Bot API Abuse in Middle East Government Espionage Campaign

An East Asian threat actor is targeting Middle Eastern government entities using a multi-stage malware chain consisting of TELESHIM, MIXEDKEY, and BINDCLOAK. The operation leverages the Telegram Bot API for HTTPS-based Command and Control (C2), effectively blending malicious traffic with legitimate encrypted communication to bypass traditional network monitoring. To evade Endpoint Detection and Response (EDR) and automated sandboxes, the attackers utilize environmental keying, ensuring execution occurs only on specific, high-value target systems. The primary objective is long-term espionage and strategic data exfiltration from public sector organizations.

Weaponization of Telegram, Discord, and Signal for C2 and Malware Delivery

Nation-state actors, including Iranian and Russian-linked groups, are increasingly leveraging mainstream communication platforms—specifically Telegram, Discord, and Signal—to facilitate Command and Control (C2) operations and malware delivery. By utilizing these high-reputation SaaS applications, attackers mask malicious traffic within legitimate, high-volume encrypted streams, effectively bypassing traditional Network Detection and Response (NDR) and Endpoint Detection and Response (EDR) solutions. Technical implementations include the Rust-based ChaosBot malware, which utilizes Discord’s API for corporate espionage, and various Telegram-integrated payloads. This tactical shift enables persistent C2 channels, facilitates intellectual property theft, and supports targeted surveillance of dissidents through the exploitation of trusted third-party infrastructures.


LINK COPIED TO CLIPBOARD