cognitive cybersecurity intelligence

News and Analysis

Search

Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems

Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems

A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks.

The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately drawing attention.

The infection begins with an ISO image carrying a real ASUSTek RegSchdTask.exe program and a harmful companion DLL.

When launched, the program loads the attacker’s code, opening a multi-stage route that later delivers TELESHIM, MIXEDKEY, and the BINDCLOAK implant.

TELESHIM uses Telegram’s Bot API as its command channel, making malicious traffic resemble ordinary communications with a trusted online service.

Researchers from Zscaler identified the activity in July 2026 while tracking an East Asia-linked actor targeting government entities in the Middle East.

Zscaler said in a report shared with Cyber Security News (CSN) that the operators captured reconnaissance results, deployed new payloads, and maintained access through scheduled tasks.

The activity shows why Telegram bot C2 channels deserve close scrutiny when they appear on systems that have no clear business need for them.

Hackers Turn Telegram Bots Into Secret Backdoor

The attackers used TELESHIM as the first backdoor in the chain. It contacts Telegram, checks for messages sent to a specific chat, and can run commands only when they are addressed to the infected machine’s unique network identifier.

That design gives operators a low-profile way to manage compromised systems. Rather than connecting directly to a suspicious server, the malware polls a widely used service, collects instructions, executes them through Windows command tools, and returns the results in encrypted form.

TELESHIM also receives files through the bot interface, decrypts them locally, and launches them using scheduled tasks.

This combination of remote control and timed execution mirrors the persistence methods described in scheduled task persistence attacks, which can allow malware to return after a restart.

The backdoor attempts to frustrate investigation before it begins its main work. It checks for virtualized environments, examines memory characteristics, performs heavy disk activity, and hides text strings to slow down automated scanning and manual analysis.

Multi-Stage Intrusion Chain

After gaining a foothold, the operators performed system, user, network, and file discovery to understand each victim environment.

Multi-stage attack chain (Source – Zscaler)

They then selected a staging location and deployed a legitimate executable with a malicious DLL, a tactic often called sideloading, to load the next component.

The second-stage loader, MIXEDKEY, decrypts an encrypted payload using the infected device’s volume serial number as part of its key.

That means the final implant is designed to work only on the intended victim, making recovered files less useful to analysts elsewhere.

The last payload, BINDCLOAK, is a 64-bit implant that communicates with an attacker-controlled domain.

Zscaler assessed, with moderate-to-high confidence, that the operator is based in East Asia, but did not link the activity to a known threat group.

Defenders should review unexpected ISO files, abnormal DLL loading beside trusted programs, and newly created scheduled tasks.

Security teams should also investigate unusual Telegram API traffic from government workstations, especially where the messaging service is not required, while tracking broader DLL sideloading malware activity for related warning signs.

Indicators of Compromise (IoCs):-

TypeIndicatorDescriptionSHA-51297124a93766be732e8fef5a56a5346a2c1f16e31ae71372ee45fa6fd6927c7b887a4e3f2789fd11285642861190dc074c1e9a5957073f1a2afebd5160f9cc907f7f320bdCooperation protocol for the exploration of petroleum and gas English.zip, ZIP archive containing the ISO image SHA-51268926e6c958562deaae35de3d9f59de3ccb2002fe8f5cc1f511d52309625b52d1c507421c84542ac30cbe9bb8bd648bad323c37801023bf9451c1c0990452466e084340fCooperation protocol for the exploration of petroleum and gas English.img, ISO image file SHA-512087499849115eb28c4364581d2b28d0986ee99f293a30720bcc898a4a8e391f93fb9be9532529043d15e9111ba284f1d8a9e4b3f58e071c6b69c8f271d4d02feacd44e66Agreement on the Establishment of Common Border Offices English1.zip, ZIP archive containing the ISO image SHA-512b776eb638fbb535708fb92b12fcc17312377c47cfde148c2140faa7105628174f9c4d56ddb11ff3f37a8b2aa25c480871504b886a6364167ecb501eacf7345f6bbf9582bAgreement on the Establishment of Common Border Offices English.img, ISO image file SHA-5127cbc51ada1a4aec88660ec32c408114bf46c01a5be2e08e36d4ec3302a8650a6ed25ec145c2fe953da53da66fbcbb3be0fd6b63907c10714c337f287b2fc258857bbff6dAsTaskSched.dll, TELESHIM new variant SHA-5123f60d53a2b5737d77e058d9e33cbe9eb1099bf51e53bd5fb32401edb4e0be841d8486b19cac1f37beaa814461f7709a073aeec468c74e5d70AsTaskSched.dll, TELESHIM old variant SHA-512f7d693a9e367ece4a3a78be28b47bdf16d7af6f8ec21218eac9145afee6806c96f87bf1e240a2eb6fd7e045101d58d30637069c7052118fd5c0f1113541bdd35e5f71cd9689f2516045da152c6fa8d9dlpprem64.dll, TELESHIM old variant SHA-51278a4f8574830bf7fbaf63d7da09be2b8ee287d6a09295502ab2407aec336f9f0d8477d683b3eaea783fd6dab90f0408274bf8a9c49adbdc70c0efd70658d65b0e1684a3fpthreadVC2.dll, MIXEDKEY reflective PE loader SHA-5127a14a99d70d42d3f7bf72f843185fc07577b1cc894636f4ac5ad670b0079b9b7ade137c33b0c658ebaa2bae80af97f390b9b2bb20a2f815eb584b2251255e84da4fa669dBINDCLOAK C2 domaincert.hypersnet.comBINDCLOAK command-and-control domain 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems appeared first on Cyber Security News.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts