started · updated
East Asian Hackers Deploy New Malware Against Middle East Governments and Alibaba Developers
Researchers have identified a previously undocumented East Asian threat actor running a sophisticated campaign against Middle East government agencies. The group introduced three new malware families—TELESHIM, MIXEDKEY and BINDCLOAK—that use the Telegram API for command‑and‑control, heavy code obfuscation and environmental keying to ensure execution only on intended targets. Activity was observed primarily between 7‑9 July 2026, with post‑compromise reconnaissance of systems, users and networks.
In a separate supply‑chain attack, malicious npm packages masquerading as private Alibaba tools have been used to deliver a cross‑platform remote‑access trojan to developers. The packages imitate Alibaba‑related names, pull malicious code from an attacker‑controlled GitHub repository, and install a RAT capable of data theft, command execution and persistence on macOS, Windows and Linux. Although download numbers are limited, the operation poses a significant espionage risk for affected organizations.
Entities
Alibaba Group · Middle East government agencies · Telegram · Zscaler ThreatLabz · npm