TELESHIM Malware Leverages Telegram for Stealthy Command and Control in Middle East Cyberattacks

TELESHIM Malware Leverages Telegram for Stealthy Command and Control in Middle East Cyberattacks

Attackers are abusing Telegram's API to remotely control malware in campaigns targeting government entities, posing risks to website hosting and infrastructure security.

A newly observed malware campaign dubbed TELESHIM has been exploiting Telegram’s communication platform to establish covert command-and-control (C2) channels for attacks aimed at government targets in the Middle East. By abusing Telegram’s robust API and encrypted messaging infrastructure, threat actors can issue commands and exfiltrate data while blending in with legitimate traffic, making detection significantly harder for conventional security tools.

The technical mechanism involves embedding Telegram Bot API tokens directly into the malware payload. Once a system is infected, TELESHIM initiates contact with a Telegram bot under the attacker’s control, using it to receive instructions, download additional modules, or upload stolen information. Because Telegram’s traffic is encrypted and to outward appearances simply connects to a popular messaging service, network defenders often fail to block or flag the activity—allowing the malware to persist inside compromised environments for extended periods.

For website owners and hosting providers, such tactics heighten the risk of server compromise. A hacked web server could be enrolled as a relay node, serve as a staging ground for phishing pages, or be used to distribute the malware to visitors through drive-by downloads. Since many modern web applications and content management systems rely on outbound API calls for legitimate features, distinguishing malicious Telegram API requests from normal operations becomes a non-trivial challenge. Organisations that fail to monitor outbound traffic and restrict unnecessary services may inadvertently host malicious infrastructure without realising it.

To guard against threats like TELESHIM, security teams should implement strict egress filtering, block unauthorised API endpoints at the network perimeter, and deploy endpoint detection rules that flag anomalous Telegram traffic from non-user systems. Website administrators must keep all CMS plugins, themes, and server software patched and employ file integrity monitoring to spot unexpected changes. Regular audits of outbound connections from hosting environments can reveal compromise before serious damage occurs.

For businesses hosting websites, managed platforms such as AEU Hosting bring an extra layer of defence by combining hardened server configurations, real-time malware scanning, and automatic core updates—making it far more difficult for attackers to gain the initial foothold needed to deploy C2 implants like TELESHIM.