ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT
ID: b3c62bcc-9351-580b-9294-7f4f77150930
STIX ID: report--b3c62bcc-9351-580b-9294-7f4f77150930
Feed Name: Sysdig Blog
Threat Score
**Executive Summary:** Sysdig TRT identified and analyzed ZynorRAT, a Go-based Remote Access Trojan using a Telegram bot as C2 that provides file exfiltration, remote shell execution, screenshots, process control, and systemd persistence; multiple Linux and Windows samples and IoCs were collected, Telegram interactions and artifacts suggest Turkish origin and early-stage development and testing on cloud instances, and detection rules/YARA and mitigation guidance are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
