TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
News Source : Internet
News Summary
- Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia.
- The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK.
- Based on the threat actor's public IP address and the system locale configured on their Windows server, the geolocation of the IP address, and the active operational hours, it's assessed with moderate-to-high confidence that the campaign is the work of an adversary.
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East.
Never miss a story from us, subscribe to our newsletter