Telegram-Based ResokerRAT Adds Screenshot Capture and Persistence
ID: 20317ba7-ac94-5cbc-b766-971654eb6ad0
STIX ID: report--20317ba7-ac94-5cbc-b766-971654eb6ad0
Feed Name: GBHackers
ResokerRAT is a Telegram‑controlled Windows Remote Access Trojan that uses the Telegram Bot API for command-and-control and exfiltration, implements anti‑analysis and privilege escalation techniques (mutex, IsDebuggerPresent, ShellExecuteExA "runas"), disables/blocks system defenses (kills monitoring tools, disables Task Manager, manipulates UAC settings), captures screenshots and downloads payloads via hidden PowerShell, and maintains persistence via HKCU Run keys; the report maps behaviors to MITRE ATT&CK and provides at least one IOC (Resoker.exe hash) and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
