ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT
ID: 41c0bc1e-559d-57d4-93da-874acb623860
STIX ID: report--41c0bc1e-559d-57d4-93da-874acb623860
Feed Name: Sysdig Blog
Threat Score
Sysdig Threat Research Team discovered and reverse-engineered ZynorRAT, a Go-compiled Remote Access Trojan controlled via a Telegram bot. ZynorRAT provides file exfiltration, screenshots, system and process enumeration, persistence via user systemd services, and arbitrary command execution; the report includes multiple Linux and Windows sample hashes, a YARA rule, Telegram C2 artifacts, evidence of active testing, and likely Turkish origin.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
