Cyber Warfare · Today's Signal

TELESHIM Turns Telegram Into a Command Channel for Gov Hacks

Published 2026-07-27 · SAL Cyber Command Intelligence Network
TELESHIM Turns Telegram Into a Command Channel for Gov Hacks

A campaign tracked as TELESHIM is using Telegram as its command-and-control channel in attacks against Middle East government targets, according to The Hacker News. The reporting doesn't detail the initial access vector or payload specifics, but the core mechanic is clear: attacker infrastructure rides on top of a legitimate, widely-used messaging platform rather than dedicated malicious servers.

This is not a new trick, it's a maturing one. Using Telegram, Discord, Slack, or GitHub for C2 has become a standard evasion move because these domains are almost never blocked at the network edge -- blocking them breaks business communication, so defenders whitelist them by default. Nation-state and criminal operators alike have learned that the fastest way past a firewall isn't a zero-day, it's borrowing trust already extended to a consumer app. When the target set is government ministries in a geopolitically contested region, that usually signals espionage-motivated tasking rather than opportunistic crime -- the attacker wants durable, quiet access, not a quick payout.

The SAL read: if your security stack treats "Telegram traffic" as automatically benign, you have a blind spot that a nation-state playbook already knows how to walk through -- get egress monitoring and anomaly detection on messaging-app traffic now, don't wait for a named CVE to force the issue.

Sources: THE HACKER NEWS

More from SOVEREIGN SIGNAL

SAL SENTRY — your private AI security operations center.24/7 watch on network, cloud, endpoints, and email. Flat $999/mo. Live in 48 hours.