logo

Triton RAT Exploits Telegram to Remotely Access and Control Infected Systems

ID: cafcdc3f-b30b-5669-90f5-56a6f526b413

STIX ID: report--cafcdc3f-b30b-5669-90f5-56a6f526b413

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-03-31

Date Updated: 2026-04-13

Author: Mandvi

...
...

Cado Security Labs uncovered Triton RAT, an open-source Python Remote Access Tool that leverages Telegram for C2 to steal credentials (including Roblox .ROBLOSECURITY cookies), keylogs, records screen/webcam, and performs file transfer and shell execution; it uses VBScript/BAT persistence, anti-analysis checks, and lists IOCs such as ProtonDrive.exe, updateagent.vbs, and check.bat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.