logo

ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT

ID: 41c0bc1e-559d-57d4-93da-874acb623860

STIX ID: report--41c0bc1e-559d-57d4-93da-874acb623860

Feed Name: Sysdig Blog

Threat Score
70/100

Date Published: 2025-09-09

Date Updated: 2026-05-01

...
...

Sysdig Threat Research Team discovered and reverse-engineered ZynorRAT, a Go-compiled Remote Access Trojan controlled via a Telegram bot. ZynorRAT provides file exfiltration, screenshots, system and process enumeration, persistence via user systemd services, and arbitrary command execution; the report includes multiple Linux and Windows sample hashes, a YARA rule, Telegram C2 artifacts, evidence of active testing, and likely Turkish origin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.