Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Targeted Attack on Government Entities in the Middle East | Part 1

0
Medium
Published: 07/20/2026 (07/20/2026, 19:29:47 UTC)
Source: AlienVault OTX General

Description

In July 2026, a sophisticated multi-stage cyberattack targeted government entities in the Middle East. The threat actor, linked to East Asia, deployed novel malware families including TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM abuses the Telegram API for covert command-and-control communications, using advanced code obfuscation. MIXEDKEY uses environmental keying derived from the victim's volume serial number to decrypt its payload. The attacker employed advanced techniques such as DLL sideloading, hypervisor detection, RAM speed checks, and staged operations to evade detection. Post-compromise activities focused on reconnaissance and persistence establishment during East Asian working hours.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/21/2026, 10:46:42 UTC

Technical Analysis

This threat involves a targeted attack campaign against Middle Eastern government entities by an East Asia-linked actor using previously undocumented malware. TELESHIM leverages Telegram API for command-and-control, blending malicious traffic with legitimate communications and employing control flow flattening and mixed boolean arithmetic for obfuscation. MIXEDKEY acts as a reflective loader that derives decryption keys from the victim machine's volume serial number, implementing environmental keying to hinder analysis. The campaign uses DLL sideloading for execution, anti-analysis techniques including hypervisor detection and RAM speed checks, and carefully staged operations to avoid detection. Post-compromise activity between July 7-9, 2026, included systematic reconnaissance and persistence establishment, with operations timed to East Asian working hours. No known exploits in the wild or patches are reported, and the threat targets specific government entities in the Middle East.

Potential Impact

The campaign enables persistent unauthorized access to targeted government networks in the Middle East, facilitating reconnaissance and potential further malicious activity. The use of novel malware with advanced evasion and obfuscation techniques complicates detection and response efforts. The environmental keying and anti-analysis methods increase the difficulty of forensic investigation and malware removal. Although no direct exploitation of software vulnerabilities is described, the threat actor's advanced tradecraft poses a significant risk to confidentiality and operational security of affected entities.

Mitigation Recommendations

No official patches or fixes are available as this campaign uses custom malware and tradecraft rather than exploiting known software vulnerabilities. Organizations should focus on detection and response capabilities tailored to the described malware behaviors, such as monitoring for abnormal Telegram API usage, DLL sideloading patterns, and indicators of environmental keying. Enhanced endpoint detection and response (EDR) solutions capable of identifying obfuscation and anti-analysis techniques are recommended. Incident response teams should review network and host telemetry for signs of the described malware families and tactics. Since this is a targeted campaign, organizations in the Middle East government sector should increase vigilance and threat hunting efforts accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-1"]
Adversary
null
Pulse Id
6a5e772bc58d968a512e89c4
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash087499849115eb28c4364581d2b28d09
hash28b47bdf16d7af6f8ec21218eac9145a
hash3f60d53a2b5737d77e058d9e33cbe9eb
hash68926e6c958562deaae35de3d9f59de3
hash78a4f8574830bf7fbaf63d7da09be2b8
hash7a14a99d70d42d3f7bf72f843185fc07
hash7cbc51ada1a4aec88660ec32c408114b
hash97124a93766be732e8fef5a56a5346a2
hashb776eb638fbb535708fb92b12fcc1731
hashc99f29ac08454855b3d538960bb2f34f
hash1099bf51e53bd5fb32401edb4e0be841d8486b19
hash2377c47cfde148c2140faa7105628174f9c4d56d
hash577b1cc894636f4ac5ad670b0079b9b7ade137c3
hash86ee99f293a30720bcc898a4a8e391f93fb9be95
hashc1f16e31ae71372ee45fa6fd6927c7b887a4e3f2
hashccb2002fe8f5cc1f511d52309625b52d1c507421
hashee287d6a09295502ab2407aec336f9f0d8477d68
hashf46c01a5be2e08e36d4ec3302a8650a6ed25ec14
hashfee6806c96f87bf1e240a2eb6fd7e045101d58d3
hash0637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9
hash32529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66
hash3b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d
hash3b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f
hash5c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6d
hash789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd
hashc84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f
hashcac1f37beaa814461f7709a073aeec468c74e5d70f7d693a9e367ece4a3a78be
hashdb11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582b

Domain

ValueDescriptionCopy
domaincert.hypersnet.com

Threat ID: 6a5f49772a4a8d5989f62c1d

Added to database: 07/21/2026, 10:27:03 UTC

Last enriched: 07/21/2026, 10:46:42 UTC

Last updated: 07/21/2026, 15:29:56 UTC

Views: 57

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses