logo

New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems

ID: 87426b28-21dc-5d93-bb63-06207d6bff86

STIX ID: report--87426b28-21dc-5d93-bb63-06207d6bff86

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

ResokerRAT is a Windows Remote Access Trojan that abuses the Telegram Bot API for stealthy command-and-control; it supports screen capture, keylogging, privilege escalation, Task Manager/process termination, persistence via Run registry, UAC weakening, and downloading additional payloads. The report details anti-analysis behaviour (IsDebuggerPresent, custom exception handling), a mutex named "Global\ResokerSystemMutex", use of SetWindowsHookExW for a global keyboard hook, and hardcoded Telegram bot token/chat ID polling. Recommended mitigations include monitoring outbound traffic to Telegram API endpoints, restricting PowerShell execution, and keeping endpoints and security software updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.