China-Linked Hackers Hit Middle East Governments With New Malware That Hides in Telegram

Zscaler researchers say a group tied to East Asia is running fresh spy operations against government networks, using three never-before-seen tools.

ThreatVectr Newsdesk· 3 min read
Aerial view of a Southeast Asian power plant at night, with a cybersecurity threat theme
Share

Key points

  • Zscaler ThreatLabz detected a new spying campaign against Middle Eastern government bodies earlier this month.
  • The attackers are linked to East Asia and are believed to be state-aligned.
  • Three previously unknown malware families were used: TELESHIM, MIXEDKEY and BINDCLOAK.
  • TELESHIM abuses the Telegram messaging service to receive orders from its operators.
  • No victim names, ransom demands or data leaks are involved. This looks like classic espionage.

Government offices in the Middle East are the latest target of a hacking crew that researchers say has ties to East Asia. The goal appears to be quiet intelligence gathering, not extortion.

The campaign was flagged by Zscaler ThreatLabz, the research arm of a cloud security firm, which said it spotted the activity earlier this month. The report was first covered by The Hacker News.

Who is behind this?

Zscaler attributes the intrusions to a group with links to East Asia. The company has not publicly named a specific country or crew, but the profile fits a state-aligned espionage operation rather than a criminal one. There is no leak site, no ransom note, no public list of victims. That is normal for spies. They want to stay inside networks and read what is there.

Unlike the ransomware gangs that dominate cybercrime headlines, groups of this type do not lock files or demand payment. They sit quietly and collect.

What is the new malware?

The researchers documented three tools that had not been seen before. Each one does a different job in the attack chain.

Malware Role
TELESHIM Backdoor that takes orders through Telegram
MIXEDKEY Custom loader that decrypts and runs the next stage
BINDCLOAK Component used to hide the attackers' presence on the machine

A backdoor is a hidden program that lets an outsider control a computer as if they were sitting at the keyboard. A loader is a smaller program whose only job is to unpack and start the main malware, often to slip past antivirus scanners.

The most notable of the three is TELESHIM. It uses Telegram, the popular messaging app, as its command channel. That means the attackers can send instructions to infected government computers by posting into a Telegram channel or bot, and the malware quietly reads them.

Why does using Telegram matter?

Because it hides in normal traffic. Most companies and government offices do not block Telegram, and its servers look harmless to security tools. Malware that talks to a random address in an unfamiliar country stands out. Malware that talks to Telegram blends in.

This trick, sometimes called "living off trusted services," has become common. Criminals and spies have used Discord, Dropbox, GitHub and Slack the same way. Defenders end up chasing a needle in a very large, very legitimate haystack.

Should ordinary people worry?

Not directly. The targets here are government agencies, and the aim is espionage. Members of the public are not being scammed or having personal accounts drained.

The wider point is simpler. Foreign intelligence services are still hammering away at Middle Eastern government networks, and the tools they use keep getting quieter. For anyone working inside those agencies, unusual Telegram traffic on office machines is now a warning sign worth taking seriously.

Zscaler has not disclosed which countries were hit, how the attackers first got in, or how long they were inside before being noticed. Those details often emerge in follow-up reporting from incident responders. For now, the headline is the toolkit: three fresh pieces of malware, one of them phoning home through an app on almost everyone's phone.

© 2026 Threat Vectr