{"id":11887,"date":"2026-04-06T10:03:40","date_gmt":"2026-04-06T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/06\/new-resokerrat-uses-telegram-bot-api-to-control-infected-windows-systems\/"},"modified":"2026-04-06T10:03:40","modified_gmt":"2026-04-06T10:03:40","slug":"new-resokerrat-uses-telegram-bot-api-to-control-infected-windows-systems","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/06\/new-resokerrat-uses-telegram-bot-api-to-control-infected-windows-systems\/","title":{"rendered":"New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems"},"content":{"rendered":"<p>    New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A new Remote Access Trojan (RAT) called ResokerRAT has been found targeting Windows systems by abusing Telegram\u2019s widely used Bot API to receive commands and send stolen data back to attackers. <\/p>\n<p>Unlike traditional malware that relies on custom command-and-control servers, this threat routes all communications through a trusted messaging platform, making it far harder for security tools to detect and block. <\/p>\n<p>The approach gives attackers a well-disguised line of communication that blends into everyday web traffic.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/50609d74-a5f7-465a-91ae-049bddbde8b9\/New-ResokerRAT-Uses-Telegram-Bot-API-to-Control-Infected-Windows-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYETIEMUC4P&amp;Signature=7J1AR5Rvo4FJ4sMskAr0H7bGUhY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIC2St2ugWysnJHzsZtfAi5xDsMzFeMb%2BPAZSa1zgeIMPAiEAz%2FIsfMRgnA2%2BO37p7z4Dw%2Bi9FgP5KBSLC%2FTf1hm1Fdwq%2FAQIxv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDGi22wZ%2Fxj9tXt6RHSrQBFVpBtOsSWh2jV9nmL7usrdJHmchr5BO1m18FKoNuoSlX0pmb29Y8xxduGpCaPmSB5xiF6BlFHhnJTZfAbojUqLnQuvMg23fo%2FxYfTZoMblHOjt2ujud5fWEDjO7TMAVguZeq%2BJrR%2FJFo%2B0kqLFAlUTbEvCpagW59cnitW3uYjLTRP8YStujhN2PlyUoR5oB2IH7Jjur8fFGn53Oqcm2uuKltfwF4TxNhGMLTI4Z3ns5ecyShY92s8BxopmWmydBqBcTX%2BJBooc3J%2F1rNh1waOx8i0yiDVmeOD6JExK7cRmKrIk3AQWdaOPZ%2FMZFexy2y3YexcfhURw%2BOH6uLSL4Rs5RTAcs7CobvS5npu9KLhmClweHtVD0TP%2By2rrqEA6opv%2F1574DUqAw6pNzwWwT%2FqGAJfSPiQ%2FnD2rRsdd28VntWDEj27brDpAlRTYSsFLEB999OiyYO6Awj%2BgpzkVvMHG1N4xNZ5v4bEiXBKQ4O8bz5Srn80d8h6Gch2AypERgwzMLs71DhO2bmyp655Mc5U4QD2ye%2BSaF1nYKptgUqVHE0tWnmJjVoN87O%2B8nqPZuX6waKzSKdGyf9ZKVQf2KHUEZaAM%2B7ihFkaTbh1%2FziWAW7N6iIoWX%2FbaQJz3QlvV5WZLNMnFsG5ld%2BEA6Lreck%2Fd5ZWmqO%2FCBmaA%2BhVQ52Gb5VAOnaeyPU4jsB8pckLsHz17O60Iy4MUCzY3A6XxvREupTraxHFyHdN8zkHCwUX6rJiXbLzg3vdbqaTH3tu%2FH0EohWUOmP3Ucrhik4P3IEeIw7IDNzgY6mAFCcem0OYk4WRGn%2FHaruRErrnZhVoW1I6zetKmtY7ca%2B30C3y%2F%2Bqim8oWA9r0eDwTroMTkrm8ckNcw8szsGd1KAJ%2BZzbbb%2FjbsJOKVSzze2Ak68PbA8v8CkpRsPXbE15b2lxIk5YYHZm0UtY0CGZWddwCkEHrg6AyPua5Ab08wQltBYpcqbsRHUN27oAmTZFFuQWXvVZIvGyA%3D%3D&amp;Expires=1775453853\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>ResokerRAT carries a wide range of harmful capabilities, including screen capture, keylogging, privilege escalation, Task Manager blocking, and downloading additional malicious payloads onto the infected machine. <\/p>\n<p>Once installed, the malware operates silently in the background, communicating through an encrypted HTTPS connection to Telegram\u2019s API without showing any visible signs to the victim. <\/p>\n<p>Since the connections to Telegram are generally trusted by corporate firewalls and network monitoring filters, this method of delivering commands is particularly effective at staying hidden for extended periods.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/50609d74-a5f7-465a-91ae-049bddbde8b9\/New-ResokerRAT-Uses-Telegram-Bot-API-to-Control-Infected-Windows-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYETIEMUC4P&amp;Signature=7J1AR5Rvo4FJ4sMskAr0H7bGUhY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIC2St2ugWysnJHzsZtfAi5xDsMzFeMb%2BPAZSa1zgeIMPAiEAz%2FIsfMRgnA2%2BO37p7z4Dw%2Bi9FgP5KBSLC%2FTf1hm1Fdwq%2FAQIxv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDGi22wZ%2Fxj9tXt6RHSrQBFVpBtOsSWh2jV9nmL7usrdJHmchr5BO1m18FKoNuoSlX0pmb29Y8xxduGpCaPmSB5xiF6BlFHhnJTZfAbojUqLnQuvMg23fo%2FxYfTZoMblHOjt2ujud5fWEDjO7TMAVguZeq%2BJrR%2FJFo%2B0kqLFAlUTbEvCpagW59cnitW3uYjLTRP8YStujhN2PlyUoR5oB2IH7Jjur8fFGn53Oqcm2uuKltfwF4TxNhGMLTI4Z3ns5ecyShY92s8BxopmWmydBqBcTX%2BJBooc3J%2F1rNh1waOx8i0yiDVmeOD6JExK7cRmKrIk3AQWdaOPZ%2FMZFexy2y3YexcfhURw%2BOH6uLSL4Rs5RTAcs7CobvS5npu9KLhmClweHtVD0TP%2By2rrqEA6opv%2F1574DUqAw6pNzwWwT%2FqGAJfSPiQ%2FnD2rRsdd28VntWDEj27brDpAlRTYSsFLEB999OiyYO6Awj%2BgpzkVvMHG1N4xNZ5v4bEiXBKQ4O8bz5Srn80d8h6Gch2AypERgwzMLs71DhO2bmyp655Mc5U4QD2ye%2BSaF1nYKptgUqVHE0tWnmJjVoN87O%2B8nqPZuX6waKzSKdGyf9ZKVQf2KHUEZaAM%2B7ihFkaTbh1%2FziWAW7N6iIoWX%2FbaQJz3QlvV5WZLNMnFsG5ld%2BEA6Lreck%2Fd5ZWmqO%2FCBmaA%2BhVQ52Gb5VAOnaeyPU4jsB8pckLsHz17O60Iy4MUCzY3A6XxvREupTraxHFyHdN8zkHCwUX6rJiXbLzg3vdbqaTH3tu%2FH0EohWUOmP3Ucrhik4P3IEeIw7IDNzgY6mAFCcem0OYk4WRGn%2FHaruRErrnZhVoW1I6zetKmtY7ca%2B30C3y%2F%2Bqim8oWA9r0eDwTroMTkrm8ckNcw8szsGd1KAJ%2BZzbbb%2FjbsJOKVSzze2Ak68PbA8v8CkpRsPXbE15b2lxIk5YYHZm0UtY0CGZWddwCkEHrg6AyPua5Ab08wQltBYpcqbsRHUN27oAmTZFFuQWXvVZIvGyA%3D%3D&amp;Expires=1775453853\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/labs.k7computing.com\/index.php\/resoker-a-telegram-based-remote-access-trojan\/\" id=\"https:\/\/labs.k7computing.com\/index.php\/resoker-a-telegram-based-remote-access-trojan\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Analysts at K7 Security Labs identified and documented this malware<\/a>, with researcher Priyadharshini publishing a detailed technical report on March 30, 2026. <\/p>\n<p>Their investigation found that the malware executable, Resoker.exe, begins its attack chain immediately upon execution, running a series of pre-checks and evasion routines before making contact with the attacker\u2019s Telegram bot.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhp5HqblPX1I0d7HagYvGZaEuLqmR_ipbjGbx3lRT52llp4zRsBvIh0_MdaAnQW0H-8wbM9Jca04OxTsKuU52bR4Dbo2yiztjKEbu5zJ2WgCrvQXogyouNUFTsRvE5yQQJsrZCUBzmeZaPCO0IarsVP0ZQQoqZDWX_u7khnm_VZtCjxLewtrLchYTriJ3A\/s16000\/Resoker.exe%2520%28Source%2520-%2520K7%2520Security%2520Labs%29.webp?ssl=1\" alt=\"Resoker.exe (Source - K7 Security Labs)\"><figcaption class=\"wp-element-caption\">Resoker.exe (Source \u2013 K7 Security Labs)<\/figcaption><\/figure>\n<\/div>\n<p>The team noted that the malware combines Windows API calls with hidden <a href=\"https:\/\/cybersecuritynews.com\/new-yurei-ransomware-with-powershell-commands\/\" id=\"126128\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell commands<\/a> to carry out its tasks without drawing the user\u2019s attention.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/50609d74-a5f7-465a-91ae-049bddbde8b9\/New-ResokerRAT-Uses-Telegram-Bot-API-to-Control-Infected-Windows-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYETIEMUC4P&amp;Signature=7J1AR5Rvo4FJ4sMskAr0H7bGUhY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIC2St2ugWysnJHzsZtfAi5xDsMzFeMb%2BPAZSa1zgeIMPAiEAz%2FIsfMRgnA2%2BO37p7z4Dw%2Bi9FgP5KBSLC%2FTf1hm1Fdwq%2FAQIxv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDGi22wZ%2Fxj9tXt6RHSrQBFVpBtOsSWh2jV9nmL7usrdJHmchr5BO1m18FKoNuoSlX0pmb29Y8xxduGpCaPmSB5xiF6BlFHhnJTZfAbojUqLnQuvMg23fo%2FxYfTZoMblHOjt2ujud5fWEDjO7TMAVguZeq%2BJrR%2FJFo%2B0kqLFAlUTbEvCpagW59cnitW3uYjLTRP8YStujhN2PlyUoR5oB2IH7Jjur8fFGn53Oqcm2uuKltfwF4TxNhGMLTI4Z3ns5ecyShY92s8BxopmWmydBqBcTX%2BJBooc3J%2F1rNh1waOx8i0yiDVmeOD6JExK7cRmKrIk3AQWdaOPZ%2FMZFexy2y3YexcfhURw%2BOH6uLSL4Rs5RTAcs7CobvS5npu9KLhmClweHtVD0TP%2By2rrqEA6opv%2F1574DUqAw6pNzwWwT%2FqGAJfSPiQ%2FnD2rRsdd28VntWDEj27brDpAlRTYSsFLEB999OiyYO6Awj%2BgpzkVvMHG1N4xNZ5v4bEiXBKQ4O8bz5Srn80d8h6Gch2AypERgwzMLs71DhO2bmyp655Mc5U4QD2ye%2BSaF1nYKptgUqVHE0tWnmJjVoN87O%2B8nqPZuX6waKzSKdGyf9ZKVQf2KHUEZaAM%2B7ihFkaTbh1%2FziWAW7N6iIoWX%2FbaQJz3QlvV5WZLNMnFsG5ld%2BEA6Lreck%2Fd5ZWmqO%2FCBmaA%2BhVQ52Gb5VAOnaeyPU4jsB8pckLsHz17O60Iy4MUCzY3A6XxvREupTraxHFyHdN8zkHCwUX6rJiXbLzg3vdbqaTH3tu%2FH0EohWUOmP3Ucrhik4P3IEeIw7IDNzgY6mAFCcem0OYk4WRGn%2FHaruRErrnZhVoW1I6zetKmtY7ca%2B30C3y%2F%2Bqim8oWA9r0eDwTroMTkrm8ckNcw8szsGd1KAJ%2BZzbbb%2FjbsJOKVSzze2Ak68PbA8v8CkpRsPXbE15b2lxIk5YYHZm0UtY0CGZWddwCkEHrg6AyPua5Ab08wQltBYpcqbsRHUN27oAmTZFFuQWXvVZIvGyA%3D%3D&amp;Expires=1775453853\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Once running, Resoker.exe creates a mutex named \u201cGlobalResokerSystemMutex\u201d to ensure only one instance of the malware runs at a time.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhmQjl_hve6d646rHtvTkiLgLRc8uFJkBhHtJWNfNXffwitAaJHu_1T8ojfZCjkg8hxmRN2ZhTeEezRV3KOZUJdX9bgJHdMDkdyMUaE_eYZkFECj7Ke4o5aJwq3YCYjIB-ARv6uX_ekpw5PmGrvQOaMyUfmxg83dA5WKPwCTV0z0ppvPkJYczt8S4fx7ug\/s16000\/Mutex%2520Creation%2520%28Source%2520-%2520K7%2520Security%2520Labs%29.webp?ssl=1\" alt=\"Mutex Creation (Source - K7 Security Labs)\"><figcaption class=\"wp-element-caption\">Mutex Creation (Source \u2013 K7 Security Labs)<\/figcaption><\/figure>\n<\/div>\n<p>It then uses the IsDebuggerPresent API to check whether a debugger or analysis tool is currently attached, and if one is found, it triggers custom exception handling to disrupt the inspection. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhy5PqofzAWUybTu4pcRg5IJAdozQCgU42ScqwGTrqjdqX78EnlCviL2Ou6qAYeYQ3pjPDra_0BTHZfJFKAqrV-WKSF2YKUpOouFnrXVKhfjlDWg5QyZe84KDUxoknOEq3663S071JQFBMkLaBRA62E6iOWvWjdSP5Oum2FplCqU_MEe9FPQ92p1_F6CDk\/s16000\/Anti-Analysis%2520Debugger%2520Check%2520%28Source%2520-%2520K7%2520Security%2520Labs%29.webp?ssl=1\" alt=\"Anti-Analysis Debugger Check (Source - K7 Security Labs)\"><figcaption class=\"wp-element-caption\">Anti-Analysis Debugger Check (Source \u2013 K7 Security Labs)<\/figcaption><\/figure>\n<\/div>\n<p>The malware also attempts to restart itself with administrator rights using ShellExecuteExA with the \u201crunas\u201d option\u00a0<em>(Figure 4: Administrator Privilege Request)<\/em>, giving it complete control over the infected system.<\/p>\n<p>To keep security researchers at bay, the malware actively scans running processes and terminates well-known <a href=\"https:\/\/cybersecuritynews.com\/analyzing-malwares-network-traffic\/\" id=\"83517\" target=\"_blank\" rel=\"noreferrer noopener\">analysis tools<\/a> such as Taskmgr.exe, Procexp.exe, and ProcessHacker.exe.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiIC33wd-rcwh2Up6UcSDC8VeHWNM4s3cjgngIyPDWrpjIjtVuRV03owPpYqdhaw03Vlz4ZUiMqXO8eKVdRsCf8E9xqicFKm_LPJdE_qjN_kp9W5gVDNHNjBnaYe0EANLJk6cqzzVonnNm8ltXUIRlPIjClyGWtfisSEAMCW84HdECMjs4GdDOL08fX500\/s16000\/Keyboard%2520Hook%2520Using%2520SetWindowsHookExW%2520%28Source%2520-%2520K7%2520Security%2520Labs%29.webp?ssl=1\" alt=\"Keyboard Hook Using SetWindowsHookExW (Source - K7 Security Labs)\"><figcaption class=\"wp-element-caption\">Keyboard Hook Using SetWindowsHookExW (Source \u2013 K7 Security Labs)<\/figcaption><\/figure>\n<\/div>\n<p>It also installs a global keyboard hook via SetWindowsHookExW, blocking common keyboard shortcuts such as ALT+TAB and CTRL+ALT+DEL, effectively trapping the user inside the infected session and preventing normal system interaction.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/50609d74-a5f7-465a-91ae-049bddbde8b9\/New-ResokerRAT-Uses-Telegram-Bot-API-to-Control-Infected-Windows-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYETIEMUC4P&amp;Signature=7J1AR5Rvo4FJ4sMskAr0H7bGUhY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIC2St2ugWysnJHzsZtfAi5xDsMzFeMb%2BPAZSa1zgeIMPAiEAz%2FIsfMRgnA2%2BO37p7z4Dw%2Bi9FgP5KBSLC%2FTf1hm1Fdwq%2FAQIxv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDGi22wZ%2Fxj9tXt6RHSrQBFVpBtOsSWh2jV9nmL7usrdJHmchr5BO1m18FKoNuoSlX0pmb29Y8xxduGpCaPmSB5xiF6BlFHhnJTZfAbojUqLnQuvMg23fo%2FxYfTZoMblHOjt2ujud5fWEDjO7TMAVguZeq%2BJrR%2FJFo%2B0kqLFAlUTbEvCpagW59cnitW3uYjLTRP8YStujhN2PlyUoR5oB2IH7Jjur8fFGn53Oqcm2uuKltfwF4TxNhGMLTI4Z3ns5ecyShY92s8BxopmWmydBqBcTX%2BJBooc3J%2F1rNh1waOx8i0yiDVmeOD6JExK7cRmKrIk3AQWdaOPZ%2FMZFexy2y3YexcfhURw%2BOH6uLSL4Rs5RTAcs7CobvS5npu9KLhmClweHtVD0TP%2By2rrqEA6opv%2F1574DUqAw6pNzwWwT%2FqGAJfSPiQ%2FnD2rRsdd28VntWDEj27brDpAlRTYSsFLEB999OiyYO6Awj%2BgpzkVvMHG1N4xNZ5v4bEiXBKQ4O8bz5Srn80d8h6Gch2AypERgwzMLs71DhO2bmyp655Mc5U4QD2ye%2BSaF1nYKptgUqVHE0tWnmJjVoN87O%2B8nqPZuX6waKzSKdGyf9ZKVQf2KHUEZaAM%2B7ihFkaTbh1%2FziWAW7N6iIoWX%2FbaQJz3QlvV5WZLNMnFsG5ld%2BEA6Lreck%2Fd5ZWmqO%2FCBmaA%2BhVQ52Gb5VAOnaeyPU4jsB8pckLsHz17O60Iy4MUCzY3A6XxvREupTraxHFyHdN8zkHCwUX6rJiXbLzg3vdbqaTH3tu%2FH0EohWUOmP3Ucrhik4P3IEeIw7IDNzgY6mAFCcem0OYk4WRGn%2FHaruRErrnZhVoW1I6zetKmtY7ca%2B30C3y%2F%2Bqim8oWA9r0eDwTroMTkrm8ckNcw8szsGd1KAJ%2BZzbbb%2FjbsJOKVSzze2Ak68PbA8v8CkpRsPXbE15b2lxIk5YYHZm0UtY0CGZWddwCkEHrg6AyPua5Ab08wQltBYpcqbsRHUN27oAmTZFFuQWXvVZIvGyA%3D%3D&amp;Expires=1775453853\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"command-and-control-via-telegram\"><strong>Command-and-Control via Telegram<\/strong><\/h2>\n<p>The most distinctive element of ResokerRAT is its use of the Telegram Bot API as a full command-and-control channel. <\/p>\n<p>The malware constructs a URL with a hardcoded bot token and chat ID, then polls Telegram\u2019s getUpdates endpoint for new instructions. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjGv-DenNxa-Mez16zhCS0B5e-67SkknEu03diXsF2MCNHvvmDYC3ICVmezIo4qaX90JE7Xx1CQ0_pebLL2W8wsWDgX746-PcH9QGxGgyPkWqujHN0Ff8ey79WK0X2ql7k6__Vh4Npj9zVZ8Ok8T_ipUOeTFDrxIYHFNDXw4DRnOPaT4zf4MhcgEhKBTr4\/s16000\/Telegram%2520Bot%2520API%2520URL%2520Used%2520for%2520C2%2520Communication%2520%28Source%2520-%2520K7%2520Security%2520Labs%29.webp?ssl=1\" alt=\"Telegram Bot API URL Used for C2 Communication (Source - K7 Security Labs)\"><figcaption class=\"wp-element-caption\">Telegram Bot API URL Used for C2 Communication (Source \u2013 K7 Security Labs)<\/figcaption><\/figure>\n<\/div>\n<p>This traffic is nearly indistinguishable from regular Telegram use, as confirmed by network capture analysis.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiJavnNmTzsgMEx_Tt3VyAkDFCeA_mB8ykA_MoUrM7iBvifGg7rtJ3SIOk6JaJYXcDijmpTe7TUc1lMthX69pUyBfcaUmS8_r9gLw9D7KBPwieTnIxbaNN85YKfJnxUaSAQCTwjxfFCdAuwtkIN-C3HMyKltEfBrL2RJijBhv9rgkf6EgyPLlIMmn8w6vU\/s16000\/Command-and-Control%2520Traffic%2520Observed%2520in%2520Wireshark%2520%28Source%2520-%2520K7%2520Security%2520Labs%29.webp?ssl=1\" alt=\"Command-and-Control Traffic Observed in Wireshark (Source - K7 Security Labs)\"><figcaption class=\"wp-element-caption\">Command-and-Control Traffic Observed in Wireshark (Source \u2013 K7 Security Labs)<\/figcaption><\/figure>\n<\/div>\n<p>From this channel, attackers can issue a range of commands. The \/screenshot command runs a hidden PowerShell script to silently capture the screen and save it as a PNG file. The \/startup command drops the malware\u2019s path into the Windows Run registry key, ensuring it survives reboots. <\/p>\n<p>The \/download command fetches additional files from attacker-controlled URLs via a hidden PowerShell process. <\/p>\n<p>The \/uac-min command quietly weakens User Account Control by setting ConsentPromptBehaviorAdmin to 0, removing security prompts without the user\u2019s knowledge.<\/p>\n<p>All transmitted data is URL-encoded before delivery, and the malware keeps a local log of its own activity.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/50609d74-a5f7-465a-91ae-049bddbde8b9\/New-ResokerRAT-Uses-Telegram-Bot-API-to-Control-Infected-Windows-Systems.pdf?AWSAccessKeyId=ASIA2F3EMEYETIEMUC4P&amp;Signature=7J1AR5Rvo4FJ4sMskAr0H7bGUhY%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEP7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIC2St2ugWysnJHzsZtfAi5xDsMzFeMb%2BPAZSa1zgeIMPAiEAz%2FIsfMRgnA2%2BO37p7z4Dw%2Bi9FgP5KBSLC%2FTf1hm1Fdwq%2FAQIxv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDGi22wZ%2Fxj9tXt6RHSrQBFVpBtOsSWh2jV9nmL7usrdJHmchr5BO1m18FKoNuoSlX0pmb29Y8xxduGpCaPmSB5xiF6BlFHhnJTZfAbojUqLnQuvMg23fo%2FxYfTZoMblHOjt2ujud5fWEDjO7TMAVguZeq%2BJrR%2FJFo%2B0kqLFAlUTbEvCpagW59cnitW3uYjLTRP8YStujhN2PlyUoR5oB2IH7Jjur8fFGn53Oqcm2uuKltfwF4TxNhGMLTI4Z3ns5ecyShY92s8BxopmWmydBqBcTX%2BJBooc3J%2F1rNh1waOx8i0yiDVmeOD6JExK7cRmKrIk3AQWdaOPZ%2FMZFexy2y3YexcfhURw%2BOH6uLSL4Rs5RTAcs7CobvS5npu9KLhmClweHtVD0TP%2By2rrqEA6opv%2F1574DUqAw6pNzwWwT%2FqGAJfSPiQ%2FnD2rRsdd28VntWDEj27brDpAlRTYSsFLEB999OiyYO6Awj%2BgpzkVvMHG1N4xNZ5v4bEiXBKQ4O8bz5Srn80d8h6Gch2AypERgwzMLs71DhO2bmyp655Mc5U4QD2ye%2BSaF1nYKptgUqVHE0tWnmJjVoN87O%2B8nqPZuX6waKzSKdGyf9ZKVQf2KHUEZaAM%2B7ihFkaTbh1%2FziWAW7N6iIoWX%2FbaQJz3QlvV5WZLNMnFsG5ld%2BEA6Lreck%2Fd5ZWmqO%2FCBmaA%2BhVQ52Gb5VAOnaeyPU4jsB8pckLsHz17O60Iy4MUCzY3A6XxvREupTraxHFyHdN8zkHCwUX6rJiXbLzg3vdbqaTH3tu%2FH0EohWUOmP3Ucrhik4P3IEeIw7IDNzgY6mAFCcem0OYk4WRGn%2FHaruRErrnZhVoW1I6zetKmtY7ca%2B30C3y%2F%2Bqim8oWA9r0eDwTroMTkrm8ckNcw8szsGd1KAJ%2BZzbbb%2FjbsJOKVSzze2Ak68PbA8v8CkpRsPXbE15b2lxIk5YYHZm0UtY0CGZWddwCkEHrg6AyPua5Ab08wQltBYpcqbsRHUN27oAmTZFFuQWXvVZIvGyA%3D%3D&amp;Expires=1775453853\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Users and organizations should avoid downloading executables from untrusted links or unknown sources. Keeping Windows and all <a href=\"https:\/\/cybersecuritynews.com\/email-security-solutions\/\" id=\"5898\" target=\"_blank\" rel=\"noreferrer noopener\">security software<\/a> up to date is critical, as patches help close the gaps that malware exploits. <\/p>\n<p>Network administrators should monitor outbound connections to Telegram API endpoints for unusual or unexpected patterns. <\/p>\n<p>Restricting PowerShell execution policies and enabling <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" id=\"16588\" target=\"_blank\" rel=\"noreferrer noopener\">endpoint detection<\/a> tools can help identify and stop this type of threat before it causes serious damage.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-resokerrat-uses-telegram-bot\/\">New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-resokerrat-uses-telegram-bot\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems A new Remote Access Trojan (RAT) called ResokerRAT has been found targeting Windows systems by abusing Telegram\u2019s widely used Bot API to receive commands and send stolen data back to attackers. Unlike traditional malware that relies on custom command-and-control servers, this threat routes all [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11887","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11887"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11887"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11887\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}