Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks.

The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately drawing attention.

The infection begins with an ISO image carrying a real ASUSTek RegSchdTask.exe program and a harmful companion DLL.

When launched, the program loads the attacker’s code, opening a multi-stage route that later delivers TELESHIM, MIXEDKEY, and the BINDCLOAK implant.

TELESHIM uses Telegram’s Bot API as its command channel, making malicious traffic resemble ordinary communications with a trusted online service.

Researchers from Zscaler identified the activity in July 2026 while tracking an East Asia-linked actor targeting government entities in the Middle East.

Zscaler said in a report shared with Cyber Security News (CSN) that the operators captured reconnaissance results, deployed new payloads, and maintained access through scheduled tasks.

The activity shows why Telegram bot C2 channels deserve close scrutiny when they appear on systems that have no clear business need for them.

Hackers Turn Telegram Bots Into Secret Backdoor

The attackers used TELESHIM as the first backdoor in the chain. It contacts Telegram, checks for messages sent to a specific chat, and can run commands only when they are addressed to the infected machine’s unique network identifier.

That design gives operators a low-profile way to manage compromised systems. Rather than connecting directly to a suspicious server, the malware polls a widely used service, collects instructions, executes them through Windows command tools, and returns the results in encrypted form.

TELESHIM also receives files through the bot interface, decrypts them locally, and launches them using scheduled tasks.

This combination of remote control and timed execution mirrors the persistence methods described in scheduled task persistence attacks, which can allow malware to return after a restart.

The backdoor attempts to frustrate investigation before it begins its main work. It checks for virtualized environments, examines memory characteristics, performs heavy disk activity, and hides text strings to slow down automated scanning and manual analysis.

Multi-Stage Intrusion Chain

After gaining a foothold, the operators performed system, user, network, and file discovery to understand each victim environment.

Multi-stage attack chain (Source – Zscaler)

They then selected a staging location and deployed a legitimate executable with a malicious DLL, a tactic often called sideloading, to load the next component.

The second-stage loader, MIXEDKEY, decrypts an encrypted payload using the infected device’s volume serial number as part of its key.

That means the final implant is designed to work only on the intended victim, making recovered files less useful to analysts elsewhere.

The last payload, BINDCLOAK, is a 64-bit implant that communicates with an attacker-controlled domain.

Zscaler assessed, with moderate-to-high confidence, that the operator is based in East Asia, but did not link the activity to a known threat group.

Defenders should review unexpected ISO files, abnormal DLL loading beside trusted programs, and newly created scheduled tasks.

Security teams should also investigate unusual Telegram API traffic from government workstations, especially where the messaging service is not required, while tracking broader DLL sideloading malware activity for related warning signs.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-512 97124a93766be732e8fef5a56a5346a2c1f16e31ae71372ee45fa6fd6927c7b887a4e3f2789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bd Cooperation protocol for the exploration of petroleum and gas English.zip, ZIP archive containing the ISO image 
SHA-512 68926e6c958562deaae35de3d9f59de3ccb2002fe8f5cc1f511d52309625b52d1c507421c84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340f Cooperation protocol for the exploration of petroleum and gas English.img, ISO image file 
SHA-512 087499849115eb28c4364581d2b28d0986ee99f293a30720bcc898a4a8e391f93fb9be9532529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66 Agreement on the Establishment of Common Border Offices English1.zip, ZIP archive containing the ISO image 
SHA-512 b776eb638fbb535708fb92b12fcc17312377c47cfde148c2140faa7105628174f9c4d56ddb11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582b Agreement on the Establishment of Common Border Offices English.img, ISO image file 
SHA-512 7cbc51ada1a4aec88660ec32c408114bf46c01a5be2e08e36d4ec3302a8650a6ed25ec145c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6d AsTaskSched.dll, TELESHIM new variant 
SHA-512 3f60d53a2b5737d77e058d9e33cbe9eb1099bf51e53bd5fb32401edb4e0be841d8486b19cac1f37beaa814461f7709a073aeec468c74e5d70 AsTaskSched.dll, TELESHIM old variant 
SHA-512 f7d693a9e367ece4a3a78be28b47bdf16d7af6f8ec21218eac9145afee6806c96f87bf1e240a2eb6fd7e045101d58d30637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9d lpprem64.dll, TELESHIM old variant 
SHA-512 78a4f8574830bf7fbaf63d7da09be2b8ee287d6a09295502ab2407aec336f9f0d8477d683b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3f pthreadVC2.dll, MIXEDKEY reflective PE loader 
SHA-512 7a14a99d70d42d3f7bf72f843185fc07577b1cc894636f4ac5ad670b0079b9b7ade137c33b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669d BINDCLOAK 
C2 domain cert.hypersnet.com BINDCLOAK command-and-control domain 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.