Targeted Attack on Government Entities in the Middle East | Part 1
Essential information
- Published
- 20/07/2026 21:29
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- bindcloak code obfuscation dll sideloading east asia environmental keying government targeting middle east mixedkey telegram abuse teleshim
- Related entities
- 10 indicators, 1 observables, 19 techniques (mitre), 3 malware
Description
In July 2026, a threat actor with links to East Asia launched sophisticated attacks against government entities in the Middle East. The multi-stage campaign deployed previously undocumented malware including TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM abuses Telegram API for command-and-control communication to blend with legitimate traffic, while employing heavy code obfuscation techniques like control flow flattening and mixed boolean arithmetic. MIXEDKEY serves as a reflective loader that uses environmental keying by deriving decryption keys from the victim machine's volume serial number. The threat actor demonstrated advanced tradecraft through DLL sideloading, anti-analysis techniques including hypervisor detection and RAM speed checks, and careful staging to evade detection. Post-compromise activity revealed systematic reconnaissance and persistence establishment between July 7-9, 2026, with operations concentrated during East Asian working hours.