Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems
A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks.
The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately drawing attention.
The infection begins with an ISO image carrying a real ASUSTek RegSchdTask.exe program and a harmful companion DLL.
When launched, the program loads the attacker’s code, opening a multi-stage route that later delivers TELESHIM, MIXEDKEY, and the BINDCLOAK implant.
TELESHIM uses Telegram’s Bot API as its command channel, making malicious traffic resemble ordinary communications with a trusted online service.
Researchers from Zscaler identified the activity in July 2026 while tracking an East Asia-linked actor targeting government entities in the Middle East.
Zscaler said in a report shared with Cyber Security News (CSN) that the operators captured reconnaissance results, deployed new payloads, and maintained access through scheduled tasks.
The activity shows why Telegram bot C2 channels deserve close scrutiny when they appear on systems that have no clear business need for them.
Hackers Turn Telegram Bots Into Secret Backdoor
The attackers used TELESHIM as the first backdoor in the chain. It contacts Telegram, checks for messages sent to a specific chat, and can run commands only when they are addressed to the infected machine’s unique network identifier.
That design gives operators a low-profile way to manage compromised systems. Rather than connecting directly to a suspicious server, the malware polls a widely used service, collects instructions, executes them through Windows command tools, and returns the results in encrypted form.
TELESHIM also receives files through the bot interface, decrypts them locally, and launches them using scheduled tasks.
This combination of remote control and timed execution mirrors the persistence methods described in scheduled task persistence attacks, which can allow malware to return after a restart.
The backdoor attempts to frustrate investigation before it begins its main work. It checks for virtualized environments, examines memory characteristics, performs heavy disk activity, and hides text strings to slow down automated scanning and manual analysis.
Multi-Stage Intrusion Chain
After gaining a foothold, the operators performed system, user, network, and file discovery to understand each victim environment.

They then selected a staging location and deployed a legitimate executable with a malicious DLL, a tactic often called sideloading, to load the next component.
The second-stage loader, MIXEDKEY, decrypts an encrypted payload using the infected device’s volume serial number as part of its key.
That means the final implant is designed to work only on the intended victim, making recovered files less useful to analysts elsewhere.
The last payload, BINDCLOAK, is a 64-bit implant that communicates with an attacker-controlled domain.
Zscaler assessed, with moderate-to-high confidence, that the operator is based in East Asia, but did not link the activity to a known threat group.
Defenders should review unexpected ISO files, abnormal DLL loading beside trusted programs, and newly created scheduled tasks.
Security teams should also investigate unusual Telegram API traffic from government workstations, especially where the messaging service is not required, while tracking broader DLL sideloading malware activity for related warning signs.
Indicators of Compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems appeared first on Cyber Security News.
Tushar Subhra Dutta
Go to cyber-security-news