logo

Telegram-Based ResokerRAT Adds Screenshot Capture and Persistence

ID: 20317ba7-ac94-5cbc-b766-971654eb6ad0

STIX ID: report--20317ba7-ac94-5cbc-b766-971654eb6ad0

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-31

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ResokerRAT is a Telegram‑controlled Windows Remote Access Trojan that uses the Telegram Bot API for command-and-control and exfiltration, implements anti‑analysis and privilege escalation techniques (mutex, IsDebuggerPresent, ShellExecuteExA "runas"), disables/blocks system defenses (kills monitoring tools, disables Task Manager, manipulates UAC settings), captures screenshots and downloads payloads via hidden PowerShell, and maintains persistence via HKCU Run keys; the report maps behaviors to MITRE ATT&CK and provides at least one IOC (Resoker.exe hash) and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.