Search...

Telegram Bot API exploited in multi-stage cyberattack against government institutions

Telegram Bot API exploited in multi-stage cyberattack against government institutions

A newly identified cyberespionage campaign targeting the information systems of government institutions in the Middle East has revealed that threat actors are using Telegram bots to control backdoors deployed on compromised systems. The campaign employs legitimate software, standard Windows components and malicious DLL files to establish a multi-stage infection mechanism. Although the threat actors are estimated to be operating from East Asia, the campaign has not been attributed to any specific threat group.

The infection process begins with the execution of an ISO image containing the legitimate ASUSTek RegSchdTask.exe application alongside a malicious DLL file. Once the application is launched, the malicious DLL is loaded into the system, activating a multi-stage attack chain comprising the TELESHIM, MIXEDKEY and BINDCLOAK components.

TELESHIM, which serves as the initial backdoor, uses the Telegram Bot API as its command-and-control (C2) channel. The malware checks messages sent to a predefined chat and executes only those commands addressed to the unique network identifier of the infected device. The results generated through command execution are subsequently transmitted to the threat actors in encrypted form.

TELESHIM is also capable of receiving additional files through the bot interface, decrypting them locally and executing them through scheduled tasks. In addition, the malware attempts to detect the presence of virtualized environments, examines memory characteristics, performs intensive disk operations and conceals embedded text strings to evade automated scanning tools and complicate analysis.

After obtaining initial access to the system, the threat actors conduct reconnaissance activities involving the system, users, network configuration and file structure. During the subsequent stage, they employ the DLL sideloading technique, whereby a malicious DLL is loaded through a legitimate executable.

The MIXEDKEY loader, deployed during the second stage, uses the volume serial number of the compromised device as part of the cryptographic key required to decrypt the malicious payload. This approach ensures that the final implant can operate only on the specifically designated target system. In the final stage of the attack chain, the 64-bit BINDCLOAK implant establishes communication with the attacker-controlled domain cert[.]hypersnet[.]com.

The Computer Emergency Response Center recommends that government institutions monitor other malware campaigns employing DLL sideloading techniques and correlate relevant security events to identify potential indicators associated with similar attacks. Security teams should also investigate unusual network traffic directed towards the Telegram Bot API from government workstations where the use of Telegram is not justified by an operational or business requirement.

© 2011-2026 All rights reserved