Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Targeted Attack on Government Entities in the Middle East | Part 1

86ee99f293a30720bcc898a4a8e391f93fb9be95

TLP:CLEAR
Active

SHA-1 Hash

Description

In July 2026, a threat actor with links to East Asia launched sophisticated attacks against government entities in the Middle East. The multi-stage campaign deployed previously undocumented malware including TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM abuses Telegram API for command-and-control communication to blend with legitimate traffic, while employing heavy code obfuscation techniques like control flow flattening and mixed boolean arithmetic. MIXEDKEY serves as a reflective loader that uses environmental keying by deriving decryption keys from the victim machine's volume serial number. The threat actor demonstrated advanced tradecraft through DLL sideloading, anti-analysis techniques including hypervisor detection and RAM speed checks, and careful staging to evade detection. Post-compromise activity revealed systematic reconnaissance and persistence establishment between July 7-9, 2026, with operations concentrated during East Asian working hours.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Targeted Attack on Government Entities in the Middle East | Part 1
Pattern Type
STIX
Confidence
75%
Valid From
Jul 22, 2026 02:00
Total Sightings
0
Added
Jul 22, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 86ee99f293a30720bcc898a4a8e391f93fb9be95

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.