logo

New Golang-based backdoor relies on Telegram for C2 communication

ID: 3a481a98-88b4-5930-8ec6-0e77e2681700

STIX ID: report--3a481a98-88b4-5930-8ec6-0e77e2681700

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2025-02-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Netskope Threat Labs discovered a Golang backdoor that uses the Telegram Bot API for C2, supports remote PowerShell execution, persistence by copying to C:\Windows\Temp\svchost.exe, and self-deletion; the sample is functional but under development and includes IoCs and tentative Russian-language attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.