Targeted Attack on Government Entities in the Middle East | Part 1
In July 2026, a sophisticated multi-stage cyberattack targeted government entities in the Middle East. The threat actor, linked to East Asia, deployed novel malware families including TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM abuses the Telegram API for covert command-and-control communications, using advanced code obfuscation. MIXEDKEY uses environmental keying derived from the victim's volume serial number to decrypt its payload. The attacker employed advanced techniques such as DLL sideloading, hypervisor detection, RAM speed checks, and staged operations to evade detection. Post-compromise activities focused on reconnaissance and persistence establishment during East Asian working hours.
AI Analysis
Technical Summary
This threat involves a targeted attack campaign against Middle Eastern government entities by an East Asia-linked actor using previously undocumented malware. TELESHIM leverages Telegram API for command-and-control, blending malicious traffic with legitimate communications and employing control flow flattening and mixed boolean arithmetic for obfuscation. MIXEDKEY acts as a reflective loader that derives decryption keys from the victim machine's volume serial number, implementing environmental keying to hinder analysis. The campaign uses DLL sideloading for execution, anti-analysis techniques including hypervisor detection and RAM speed checks, and carefully staged operations to avoid detection. Post-compromise activity between July 7-9, 2026, included systematic reconnaissance and persistence establishment, with operations timed to East Asian working hours. No known exploits in the wild or patches are reported, and the threat targets specific government entities in the Middle East.
Potential Impact
The campaign enables persistent unauthorized access to targeted government networks in the Middle East, facilitating reconnaissance and potential further malicious activity. The use of novel malware with advanced evasion and obfuscation techniques complicates detection and response efforts. The environmental keying and anti-analysis methods increase the difficulty of forensic investigation and malware removal. Although no direct exploitation of software vulnerabilities is described, the threat actor's advanced tradecraft poses a significant risk to confidentiality and operational security of affected entities.
Mitigation Recommendations
No official patches or fixes are available as this campaign uses custom malware and tradecraft rather than exploiting known software vulnerabilities. Organizations should focus on detection and response capabilities tailored to the described malware behaviors, such as monitoring for abnormal Telegram API usage, DLL sideloading patterns, and indicators of environmental keying. Enhanced endpoint detection and response (EDR) solutions capable of identifying obfuscation and anti-analysis techniques are recommended. Incident response teams should review network and host telemetry for signs of the described malware families and tactics. Since this is a targeted campaign, organizations in the Middle East government sector should increase vigilance and threat hunting efforts accordingly.
Indicators of Compromise
- hash: 087499849115eb28c4364581d2b28d09
- hash: 28b47bdf16d7af6f8ec21218eac9145a
- hash: 3f60d53a2b5737d77e058d9e33cbe9eb
- hash: 68926e6c958562deaae35de3d9f59de3
- hash: 78a4f8574830bf7fbaf63d7da09be2b8
- hash: 7a14a99d70d42d3f7bf72f843185fc07
- hash: 7cbc51ada1a4aec88660ec32c408114b
- hash: 97124a93766be732e8fef5a56a5346a2
- hash: b776eb638fbb535708fb92b12fcc1731
- hash: c99f29ac08454855b3d538960bb2f34f
- hash: 1099bf51e53bd5fb32401edb4e0be841d8486b19
- hash: 2377c47cfde148c2140faa7105628174f9c4d56d
- hash: 577b1cc894636f4ac5ad670b0079b9b7ade137c3
- hash: 86ee99f293a30720bcc898a4a8e391f93fb9be95
- hash: c1f16e31ae71372ee45fa6fd6927c7b887a4e3f2
- hash: ccb2002fe8f5cc1f511d52309625b52d1c507421
- hash: ee287d6a09295502ab2407aec336f9f0d8477d68
- hash: f46c01a5be2e08e36d4ec3302a8650a6ed25ec14
- hash: fee6806c96f87bf1e240a2eb6fd7e045101d58d3
- hash: 0637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9
- hash: 32529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66
- hash: 3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d
- hash: 3b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f
- hash: 5c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6d
- hash: 789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd
- hash: c84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f
- hash: cac1f37beaa814461f7709a073aeec468c74e5d70f7d693a9e367ece4a3a78be
- hash: db11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582b
- domain: cert.hypersnet.com
Targeted Attack on Government Entities in the Middle East | Part 1
Description
In July 2026, a sophisticated multi-stage cyberattack targeted government entities in the Middle East. The threat actor, linked to East Asia, deployed novel malware families including TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM abuses the Telegram API for covert command-and-control communications, using advanced code obfuscation. MIXEDKEY uses environmental keying derived from the victim's volume serial number to decrypt its payload. The attacker employed advanced techniques such as DLL sideloading, hypervisor detection, RAM speed checks, and staged operations to evade detection. Post-compromise activities focused on reconnaissance and persistence establishment during East Asian working hours.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a targeted attack campaign against Middle Eastern government entities by an East Asia-linked actor using previously undocumented malware. TELESHIM leverages Telegram API for command-and-control, blending malicious traffic with legitimate communications and employing control flow flattening and mixed boolean arithmetic for obfuscation. MIXEDKEY acts as a reflective loader that derives decryption keys from the victim machine's volume serial number, implementing environmental keying to hinder analysis. The campaign uses DLL sideloading for execution, anti-analysis techniques including hypervisor detection and RAM speed checks, and carefully staged operations to avoid detection. Post-compromise activity between July 7-9, 2026, included systematic reconnaissance and persistence establishment, with operations timed to East Asian working hours. No known exploits in the wild or patches are reported, and the threat targets specific government entities in the Middle East.
Potential Impact
The campaign enables persistent unauthorized access to targeted government networks in the Middle East, facilitating reconnaissance and potential further malicious activity. The use of novel malware with advanced evasion and obfuscation techniques complicates detection and response efforts. The environmental keying and anti-analysis methods increase the difficulty of forensic investigation and malware removal. Although no direct exploitation of software vulnerabilities is described, the threat actor's advanced tradecraft poses a significant risk to confidentiality and operational security of affected entities.
Mitigation Recommendations
No official patches or fixes are available as this campaign uses custom malware and tradecraft rather than exploiting known software vulnerabilities. Organizations should focus on detection and response capabilities tailored to the described malware behaviors, such as monitoring for abnormal Telegram API usage, DLL sideloading patterns, and indicators of environmental keying. Enhanced endpoint detection and response (EDR) solutions capable of identifying obfuscation and anti-analysis techniques are recommended. Incident response teams should review network and host telemetry for signs of the described malware families and tactics. Since this is a targeted campaign, organizations in the Middle East government sector should increase vigilance and threat hunting efforts accordingly.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-1"]
- Adversary
- null
- Pulse Id
- 6a5e772bc58d968a512e89c4
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash087499849115eb28c4364581d2b28d09 | — | |
hash28b47bdf16d7af6f8ec21218eac9145a | — | |
hash3f60d53a2b5737d77e058d9e33cbe9eb | — | |
hash68926e6c958562deaae35de3d9f59de3 | — | |
hash78a4f8574830bf7fbaf63d7da09be2b8 | — | |
hash7a14a99d70d42d3f7bf72f843185fc07 | — | |
hash7cbc51ada1a4aec88660ec32c408114b | — | |
hash97124a93766be732e8fef5a56a5346a2 | — | |
hashb776eb638fbb535708fb92b12fcc1731 | — | |
hashc99f29ac08454855b3d538960bb2f34f | — | |
hash1099bf51e53bd5fb32401edb4e0be841d8486b19 | — | |
hash2377c47cfde148c2140faa7105628174f9c4d56d | — | |
hash577b1cc894636f4ac5ad670b0079b9b7ade137c3 | — | |
hash86ee99f293a30720bcc898a4a8e391f93fb9be95 | — | |
hashc1f16e31ae71372ee45fa6fd6927c7b887a4e3f2 | — | |
hashccb2002fe8f5cc1f511d52309625b52d1c507421 | — | |
hashee287d6a09295502ab2407aec336f9f0d8477d68 | — | |
hashf46c01a5be2e08e36d4ec3302a8650a6ed25ec14 | — | |
hashfee6806c96f87bf1e240a2eb6fd7e045101d58d3 | — | |
hash0637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9 | — | |
hash32529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66 | — | |
hash3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d | — | |
hash3b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f | — | |
hash5c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6d | — | |
hash789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd | — | |
hashc84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f | — | |
hashcac1f37beaa814461f7709a073aeec468c74e5d70f7d693a9e367ece4a3a78be | — | |
hashdb11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582b | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaincert.hypersnet.com | — |
Threat ID: 6a5f49772a4a8d5989f62c1d
Added to database: 07/21/2026, 10:27:03 UTC
Last enriched: 07/21/2026, 10:46:42 UTC
Last updated: 07/21/2026, 15:29:56 UTC
Views: 57
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.