ResokerRAT Hijacks Telegram API to Command Infected Windows PCs
ID: 65aab72e-ec96-596f-84cd-b022535dce66
STIX ID: report--65aab72e-ec96-596f-84cd-b022535dce66
Feed Name: GBHackers
ResokerRAT is a Windows remote access Trojan that abuses the Telegram Bot API as an application-layer C2 channel to issue text commands and exfiltrate data. The malware employs anti-analysis checks (mutex, IsDebuggerPresent, terminating analysis tools), installs a global keyboard hook to block defensive key combos, attempts UAC bypass and persistence via Run key, executes hidden PowerShell for screenshots and downloads, and URL-encodes data sent over HTTPS. The report maps behaviors to MITRE ATT&CK techniques, provides detection advice (monitor Telegram Bot API traffic, startup/UAC registry keys, PowerShell activity), and lists an IOC (file hash and filename).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
