Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Trump AI Safety Chief Resigns After Three Months
July 21, 2026
APT42 Targets Officials with AI Phishing, TAMECAT Malware
July 21, 2026
Critical GitHub Actions Flaw Backdoors AsyncAPI npm Packages with Miasma RAT
July 21, 2026
Home/CyberSecurity News/Telegram Bots Exploited as Backdoors in Government Systems
CyberSecurity News

Telegram Bots Exploited as Backdoors in Government Systems

Key Takeaways A newly identified cyberespionage campaign is leveraging Telegram bots to establish covert backdoors within government networks in the Middle East. The attack chain initiates with an...

David kimber
David kimber
July 21, 2026 4 Min Read
8 0

Key Takeaways

  • A newly identified cyberespionage campaign is leveraging Telegram bots to establish covert backdoors within government networks in the Middle East.
  • The attack chain initiates with an ISO image containing a legitimate ASUSTek executable (`RegSchdTask.exe`) alongside a malicious DLL, exploiting DLL sideloading.
  • The primary backdoor, TELESHIM, communicates with attackers via Telegram’s Bot API, blending malicious traffic with legitimate service communications.
  • Subsequent stages deploy MIXEDKEY and the BINDCLOAK implant, with MIXEDKEY using a unique device identifier for payload decryption, hindering analysis.
  • The threat actor, assessed to be based in East Asia, uses anti-analysis techniques to evade detection and maintain persistence through scheduled tasks.

A sophisticated cyberespionage operation has been uncovered, transforming Telegram bots into stealthy command and control (C2) channels for backdoors embedded within government systems across the Middle East. This campaign leverages standard Windows components and seemingly legitimate files to gain and maintain persistent access, effectively evading immediate detection.

Table Of Content

  • Key Takeaways
  • Initial Intrusion and TELESHIM Backdoor
  • Multi-Stage Intrusion Chain
  • What You Should Do

The attack, detailed in a report by Zscaler researchers, highlights a concerning trend where widely used communication platforms are weaponized for covert operations. Zscaler identified this activity in July 2026, attributing it to an East Asia-linked actor targeting government entities.

Initial Intrusion and TELESHIM Backdoor

The infection chain begins with a malicious ISO image. This image contains a genuine ASUSTek program, RegSchdTask.exe, paired with a harmful dynamic-link library (DLL). When the legitimate program is executed, it inadvertently loads the attacker’s malicious DLL, a technique known as DLL sideloading. This initial compromise initiates a multi-stage infection process, ultimately deploying TELESHIM, MIXEDKEY, and the BINDCLOAK implant.

TELESHIM acts as the first-stage backdoor, utilizing Telegram’s Bot API for its command and control infrastructure. This method allows malicious traffic to masquerade as benign communications with a legitimate online service, making it difficult to detect. The backdoor specifically checks for messages directed at the infected machine’s unique network identifier, ensuring that commands are executed only on the intended target.

This design provides the attackers with a low-profile mechanism for managing compromised systems. Instead of directly connecting to a suspicious C2 server, the malware periodically queries Telegram for instructions. It then executes these commands using standard Windows tools and transmits encrypted results back through the bot interface. TELESHIM also facilitates the remote delivery of additional files, which are decrypted locally and launched via scheduled tasks, establishing persistence even after system restarts.

Before initiating its core functions, TELESHIM incorporates several anti-analysis techniques. It checks for virtualized environments, analyzes memory characteristics, performs extensive disk activity, and obfuscates text strings. These measures are designed to hinder automated scanning and manual reverse engineering efforts by security researchers.

Multi-Stage Intrusion Chain

Following the initial foothold, the operators conduct extensive reconnaissance, gathering information about the victim’s system, users, network configurations, and files. This intelligence-gathering phase is crucial for understanding the environment and planning subsequent actions.

Multi-stage attack chain (Source - Zscaler)
Multi-stage attack chain (Source – Zscaler)

After reconnaissance, the attackers select a staging location and deploy MIXEDKEY, the second-stage loader. MIXEDKEY employs another DLL sideloading tactic, utilizing a legitimate executable with a malicious DLL to load its components. This loader decrypts its payload using the infected device’s volume serial number as part of the decryption key. This unique key ensures that the final implant functions only on the specific target machine, making it less useful for security analysts attempting to reverse engineer it on other systems.

The final payload in this chain is BINDCLOAK, a 64-bit implant that establishes communication with an attacker-controlled domain. Zscaler assessed with moderate-to-high confidence that the operators are based in East Asia, although they did not link this activity to any previously known threat groups. The sophistication of the attack, particularly the use of Telegram for C2 and the tailored payloads, underscores the evolving tactics of cyberespionage actors.

What You Should Do

  • Monitor for Unusual Files: Scrutinize unexpected ISO files, especially those delivered via email or untrusted sources.
  • Detect DLL Sideloading: Implement robust endpoint detection and response (EDR) solutions to detect abnormal DLL loading alongside legitimate programs, particularly for executables like RegSchdTask.exe.
  • Inspect Scheduled Tasks: Regularly audit newly created or modified scheduled tasks for suspicious entries that could indicate persistence mechanisms.
  • Analyze Network Traffic: Monitor network traffic for unusual communications with Telegram’s Bot API from government workstations, especially in environments where Telegram is not officially sanctioned or necessary for business operations.
  • Stay Informed on DLL Sideloading: Keep abreast of the latest intelligence on DLL sideloading malware activity and implement corresponding detection rules and mitigations.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-512 97124a93766be732e8fef5a56a5346a2c1f16e31ae71372ee45fa6fd6927c7b887a4e3f2789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd Cooperation protocol for the exploration of petroleum and gas English.zip, ZIP archive containing the ISO image
SHA-512 68926e6c958562deaae35de3d9f59de3ccb2002fe8f5cc1f511d52309625b52d1c507421c84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f Cooperation protocol for the exploration of petroleum and gas English.img, ISO image file

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

New PAM Guide Reveals Privilege Escalation Paths Attackers Exploit

Next Post

Critical PAN-OS Vulnerability Exploited by Qilin Ransomware Gang

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Craneware Data Breach: Attackers Stole Extensive Patient and Employee Data
July 21, 2026
AgentBaiting Campaign Uses 800 Fake AI Skills and MCP Servers to Deliver SmartLoader Malware
July 21, 2026
Outlook Vulnerability Lets Attackers Hide C2 in Calendar Events
July 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us