Malware, Threat Intelligence

Novel ResokerRAT malware exploits Telegram API to target Windows systems

Laptop screen showing malware warning sign with digital circuit background on desk in modern office environment with natural light and creative concept.

Windows systems are being subjected to intrusions involving the newly emergent ResokerRAT malware, which leverages Telegram Bot API to facilitate remote tracking and control of compromised systems, while maintaining stealth, according to GBHackers News.

After creating a mutex that ensures lone malware execution in the targeted system, ResokerRAT which obtains simple text-based commands from Telegram moves to identify attached debuggers and prompt custom exception handling should any be discovered, a report from K7 Security Labs showed. ResokerRAT also harnesses ShellExecuteEx to restart with elevated privileges while enumerating running processes and killing monitoring tools to circumvent analysis.

Aside from supporting commands for visual surveillance, persistence, and further payload retrieval, ResokerRAT also alters multiple UAC-related registry keys to hinder Windows security alerts. Such findings should prompt organizations' security teams to closely track atypical Telegram Bot API traffic and assess startup and UAC-related registry keys. Implementing up-to-date endpoint protection has also been recommended.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds