K7 Security Labs identified ResokerRAT, a Windows remote access trojan that uses Telegram’s Bot API as its command-and-control channel instead of dedicated attacker infrastructure. The malware, delivered as Resoker.exe, polls Telegram endpoints such as getUpdates with hardcoded bot credentials and chat IDs, allowing commands and stolen data to move over trusted HTTPS traffic to api.telegram.org, which can make network-based detection more difficult.
Researchers said the malware supports screen capture, keylogging, file download, privilege escalation, and persistence, while also attempting to evade analysis and disrupt defenders. ResokerRAT creates a mutex, checks for debuggers, relaunches with administrator rights, blocks tools including Task Manager and Process Hacker, weakens UAC-related settings, and adds itself to the Windows Run registry key for startup execution. Defenders were urged to monitor suspicious outbound Telegram API traffic, Run key persistence, restricted PowerShell activity, and user reports that security or system tools suddenly cannot be opened.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
News coverage publicized ResokerRAT as a Windows RAT delivered as Resoker.exe that communicates with attackers through hardcoded Telegram bot credentials over HTTPS to api.telegram.org. Reports highlighted its persistence via the Run registry key, interference with tools such as Task Manager and Process Hacker, and recommendations for defenders to monitor suspicious Telegram API traffic and related host-based indicators.
A technical report by K7 Security Labs researcher Priyadharshini documented a newly identified Windows remote access trojan called ResokerRAT. The report described its use of Telegram Bot API for command-and-control, along with capabilities including persistence, privilege escalation, anti-analysis, screenshot capture, keylogging, and downloading additional payloads.
Breakglass Intelligence published an early technical analysis of a newly documented 64-bit Windows RAT called Resoker that used the Telegram Bot API as its sole command-and-control channel. The report detailed active bot infrastructure, capabilities such as screenshots, keylogging, persistence and UAC manipulation, and multiple OPSEC failures that made the malware straightforward to detect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.