logo

ZynorRAT technical analysis: Reverse engineering a novel, Turkish Go-based RAT

ID: b3c62bcc-9351-580b-9294-7f4f77150930

STIX ID: report--b3c62bcc-9351-580b-9294-7f4f77150930

Feed Name: Sysdig Blog

Threat Score
65/100

Date Published: 2025-09-09

Date Updated: 2026-05-01

...
...

**Executive Summary:** Sysdig TRT identified and analyzed ZynorRAT, a Go-based Remote Access Trojan using a Telegram bot as C2 that provides file exfiltration, remote shell execution, screenshots, process control, and systemd persistence; multiple Linux and Windows samples and IoCs were collected, Telegram interactions and artifacts suggest Turkish origin and early-stage development and testing on cloud instances, and detection rules/YARA and mitigation guidance are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.