New Golang-based backdoor relies on Telegram for C2 communication
ID: 3a481a98-88b4-5930-8ec6-0e77e2681700
STIX ID: report--3a481a98-88b4-5930-8ec6-0e77e2681700
Feed Name: Security Affairs
Threat Score
Netskope Threat Labs discovered a Golang backdoor that uses the Telegram Bot API for C2, supports remote PowerShell execution, persistence by copying to C:\Windows\Temp\svchost.exe, and self-deletion; the sample is functional but under development and includes IoCs and tentative Russian-language attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
