Government entities in the Middle East were targeted in a July 2026 intrusion campaign that researchers linked with moderate-to-high confidence to an East Asia-based threat actor. The attack chain began with ISO or IMG lure files containing a legitimate ASUSTek executable, RegSchdTask.exe, which sideloaded a malicious DLL, AsTaskSched.dll, to deploy a newly documented backdoor called TELESHIM. Researchers said TELESHIM used heavy obfuscation, anti-analysis checks, and scheduled-task persistence, while abusing the Telegram API for command-and-control to blend malicious traffic with legitimate services.
The operation then used a reflective loader named MIXEDKEY to decrypt and launch the final BINDCLOAK implant, with decryption tied to the victim machine through environmental keying based on the volume serial number. Investigators also observed hands-on-keyboard activity after compromise, including reconnaissance, persistence creation, connectivity checks, and staged delivery of follow-on payloads, with command activity concentrated between 4 AM and 12 PM UTC. The campaign has not been attributed to a known APT group, but the malware set and tradecraft indicate a targeted espionage operation against regional government networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Gurucul published additional technical details for the Middle East government espionage campaign, including indicators of compromise such as the domain cert.hypersnet.com, multiple file hashes, and detection queries for defenders. The report also described Telegram API-based command-and-control communications used by the malware.
On 2026-07-20, Zscaler ThreatLabz published research describing the July 2026 campaign, its malware chain, and its assessment that the activity was linked to an East Asia-based threat actor. The report stated the activity was not yet attributed to a known APT group.
Researchers observed operators conducting reconnaissance, creating persistence, performing connectivity checks, and deploying next-stage payloads on compromised systems. Command timing was concentrated between 4 AM and 12 PM UTC.
The campaign used a multi-stage infection chain starting with ISO/IMG lures containing a legitimate ASUSTek executable, RegSchdTask.exe, which sideloaded a malicious DLL, AsTaskSched.dll. This chain deployed the TELESHIM backdoor, then the MIXEDKEY reflective loader, and finally the BINDCLOAK implant.
In July 2026, a targeted campaign hit government entities in the Middle East. Zscaler ThreatLabz assessed with moderate-to-high confidence that the operation was conducted by a threat actor operating from East Asia, but did not attribute it to a known APT group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecommunity.gurucul.com
Open sourcemalware.news
Open sourcezscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.