Cybersecurity News • 1h
Telegram Bot API Abuse in Middle East Government Espionage Campaign
An East Asian threat actor is targeting Middle Eastern government entities using a multi-stage malware chain consisting of TELESHIM, MIXEDKEY, and BINDCLOAK. The operation leverages the Telegram Bot API for HTTPS-based Command and Control (C2), effectively blending malicious traffic with legitimate encrypted communication to bypass traditional network monitoring. To evade Endpoint Detection and Response (EDR) and automated sandboxes, the attackers utilize environmental keying, ensuring execution occurs only on specific, high-value target systems. The primary objective is long-term espionage and strategic data exfiltration from public sector organizations.