logo

ResokerRAT Hijacks Telegram API to Command Infected Windows PCs

ID: 65aab72e-ec96-596f-84cd-b022535dce66

STIX ID: report--65aab72e-ec96-596f-84cd-b022535dce66

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

ResokerRAT is a Windows remote access Trojan that abuses the Telegram Bot API as an application-layer C2 channel to issue text commands and exfiltrate data. The malware employs anti-analysis checks (mutex, IsDebuggerPresent, terminating analysis tools), installs a global keyboard hook to block defensive key combos, attempts UAC bypass and persistence via Run key, executes hidden PowerShell for screenshots and downloads, and URL-encodes data sent over HTTPS. The report maps behaviors to MITRE ATT&CK techniques, provides detection advice (monitor Telegram Bot API traffic, startup/UAC registry keys, PowerShell activity), and lists an IOC (file hash and filename).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.