New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems
ID: 87426b28-21dc-5d93-bb63-06207d6bff86
STIX ID: report--87426b28-21dc-5d93-bb63-06207d6bff86
Feed Name: cybersecurityNews.com
ResokerRAT is a Windows Remote Access Trojan that abuses the Telegram Bot API for stealthy command-and-control; it supports screen capture, keylogging, privilege escalation, Task Manager/process termination, persistence via Run registry, UAC weakening, and downloading additional payloads. The report details anti-analysis behaviour (IsDebuggerPresent, custom exception handling), a mutex named "Global\ResokerSystemMutex", use of SetWindowsHookExW for a global keyboard hook, and hardcoded Telegram bot token/chat ID polling. Recommended mitigations include monitoring outbound traffic to Telegram API endpoints, restricting PowerShell execution, and keeping endpoints and security software updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
