ResokerRAT Uses Telegram to Hijack Your PC and Disable Your Security Keys
ID: 0641e7f5-2265-5b1a-abdc-ce6d84cce29c
STIX ID: report--0641e7f5-2265-5b1a-abdc-ce6d84cce29c
Feed Name: securityonline.info
K7 Security Labs uncovered ResokerRAT, a Remote Access Trojan that leverages the Telegram bot API as its C2 channel to covertly monitor and control infected Windows systems. The report describes technical features including a Global\ResokerSystemMutex, anti-debugging checks, privilege escalation via "runas", termination of security tools, a global keyboard hook that blocks key combinations (ALT+F4, CTRL+SHIFT+ESC, CTRL+ALT+DEL), registry changes for persistence and Task Manager disabling, UAC tampering, and Telegram-driven commands (e.g., /screenshot, /block_taskmgr, /startup, /download) enabling surveillance, payload delivery, and persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
