Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Targeted Attack on Government Entities in the Middle East | Part 1

789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd

TLP:CLEAR
Active

SHA-256 Hash

Description

In July 2026, a threat actor with links to East Asia launched sophisticated attacks against government entities in the Middle East. The multi-stage campaign deployed previously undocumented malware including TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM abuses Telegram API for command-and-control communication to blend with legitimate traffic, while employing heavy code obfuscation techniques like control flow flattening and mixed boolean arithmetic. MIXEDKEY serves as a reflective loader that uses environmental keying by deriving decryption keys from the victim machine's volume serial number. The threat actor demonstrated advanced tradecraft through DLL sideloading, anti-analysis techniques including hypervisor detection and RAM speed checks, and careful staging to evade detection. Post-compromise activity revealed systematic reconnaissance and persistence establishment between July 7-9, 2026, with operations concentrated during East Asian working hours.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Targeted Attack on Government Entities in the Middle East | Part 1
Pattern Type
STIX
Confidence
75%
Valid From
Jul 22, 2026 02:00
Total Sightings
0
Added
Jul 22, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.