logo

ResokerRAT Uses Telegram to Hijack Your PC and Disable Your Security Keys

ID: 0641e7f5-2265-5b1a-abdc-ce6d84cce29c

STIX ID: report--0641e7f5-2265-5b1a-abdc-ce6d84cce29c

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

K7 Security Labs uncovered ResokerRAT, a Remote Access Trojan that leverages the Telegram bot API as its C2 channel to covertly monitor and control infected Windows systems. The report describes technical features including a Global\ResokerSystemMutex, anti-debugging checks, privilege escalation via "runas", termination of security tools, a global keyboard hook that blocks key combinations (ALT+F4, CTRL+SHIFT+ESC, CTRL+ALT+DEL), registry changes for persistence and Task Manager disabling, UAC tampering, and Telegram-driven commands (e.g., /screenshot, /block_taskmgr, /startup, /download) enabling surveillance, payload delivery, and persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.