Zscaler ThreatLabz identified a multi-stage attack campaign targeting Middle East government entities by a threat actor linked to East Asia. The attack chain uses an ISO file to deliver the TELESHIM backdoor via DLL sideloading of a legitimate ASUS executable, with TELESHIM abusing the Telegram API for C2 communication. A second-stage loader, MIXEDKEY, uses environmental keying based on the victim's volume serial number to decrypt and reflectively load the final BINDCLOAK C2 implant, with heavy obfuscation and anti-analysis techniques throughout.
BINDCLOAK
1 post
Targeted Attack on Middle East Govts (Part 1) | ThreatLabz