Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
TELESHIM creates a scheduled task named shimgen that runs every 6 minutes and executes the binary from C:\programdata\shimgen_Data\shimgen.exe.
TELESHIM and MIXEDKEY used heavy code obfuscation techniques leveraging control flow flattening (CFF), mixed boolean arithmetic (MBA), and opaque predicates to hinder reverse engineering.
The final payload is encrypted using two layers of XOR encryption... MIXEDKEY decrypts the payload and reflectively loads it.
TELESHIM uses multiple anti-analysis techniques to evade automated analysis environments... checks bit 31 of the ECX register to detect the presence of a hypervisor... If bit 31 of ECX is set, execution terminates.
Network reconnaissance ipconfig /all ipconfig /displaydns netstat -ano Discover information about the system's network configuration and active network connections.
System reconnaissance net user ... Discover information about current users
netstat -ano ... Discover information about the system’s network configuration and active network connections.
tasklist ... Discover information about current users, list of running processes, and the hostname of the infected machine.
hostname ... Discover information about current users, list of running processes, and the hostname of the infected machine.
File reconnaissance dir c:\Users dir c:\Users\ \desktop dir c:\Users\ \Downloads dir C:\ProgramData\Crypto\DSS\ dir C:\ProgramData\ dir C:\ProgramData\Lenovo dir C:\ProgramData\Intel
TELESHIM abuses the Telegram API for C2 communication, a technique used to blend in with legitimate internet traffic.
In the next phase, TELESHIM enters a polling loop by sending HTTP GET requests to the following URL to fetch updates: https://api.telegram.org/bot /getUpdates?offset=
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 32-bit C++ Windows DLL used as the first-stage backdoor. It is sideloaded by a legitimate ASUSTek executable, installs a hook for indirect execution, performs anti-analysis checks, establishes persistence via scheduled tasks, stages payloads, and uses the Telegram API for C2 to execute commands, register infections, and download next-stage payloads.
A 32-bit C++ Windows DLL used as the first-stage backdoor. It installs a hook into a legitimate host executable for indirect execution, performs anti-analysis checks, establishes persistence via scheduled tasks, abuses the Telegram API for C2, executes commands, and downloads/decrypts next-stage payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.