TELESHIM Abusa de Telegram para C2 en Ataques Contra Gobiernos del Medio Oriente
Resumen
Investigadores de ciberseguridad han detectado una campaña maliciosa dirigida a entidades gubernamentales del Medio Oriente, asociada a un actor amenazante con vínculos en Asia Oriental. La campaña ha desplegado familias de malware previamente no reportadas como TELESHIM, MIXEDKEY y BINDCLOAK. Esta actividad maliciosa utiliza Telegram para el comando y control (C2) de los ataques.
Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this month.