216.73.216.197

Targeted Attack on Government Entities in the Middle East | Part 1

· Published 20/07/2026 21:29

Export JSON

Essential information

Published
20/07/2026 21:29
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
bindcloak code obfuscation dll sideloading east asia environmental keying government targeting middle east mixedkey telegram abuse teleshim
Related entities
10 indicators, 1 observables, 19 techniques (mitre), 3 malware

Description

In July 2026, a threat actor with links to launched sophisticated attacks against government entities in the . The multi-stage campaign deployed previously undocumented malware including TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM abuses Telegram API for command-and-control communication to blend with legitimate traffic, while employing heavy techniques like control flow flattening and mixed boolean arithmetic. MIXEDKEY serves as a reflective loader that uses environmental keying by deriving decryption keys from the victim machine's volume serial number. The threat actor demonstrated advanced tradecraft through , anti-analysis techniques including hypervisor detection and RAM speed checks, and careful staging to evade detection. Post-compromise activity revealed systematic reconnaissance and persistence establishment between July 7-9, 2026, with operations concentrated during East Asian working hours.

External references