Analysis governmentdiplomatic
TELESHIM, MIXEDKEY, BINDCLOAK: Inside the East Asia APT Campaign Against Middle East Governments
Zscaler ThreatLabz has documented a three-stage malware campaign by an unattributed East Asia-linked actor targeting Middle East government entities. The toolset — TELESHIM, MIXEDKEY, and BINDCLOAK — represents a cluster of previously undocumented malware using Telegram API C2, environmental keying, and DLL sideloading to maintain persistent covert access.