Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
remote-access-implantcommand-and-control-methodpersistence-methoddefense-evasion-method

ResokerRAT Uses Telegram Bot API to Control and Persist on Windows Hosts

Updated 2mo agoFirst seen Mar 31, 20264 sources

K7 Security Labs identified ResokerRAT, a Windows remote access trojan that uses Telegram’s Bot API as its command-and-control channel instead of dedicated attacker infrastructure. The malware, delivered as Resoker.exe, polls Telegram endpoints such as getUpdates with hardcoded bot credentials and chat IDs, allowing commands and stolen data to move over trusted HTTPS traffic to api.telegram.org, which can make network-based detection more difficult.

Researchers said the malware supports screen capture, keylogging, file download, privilege escalation, and persistence, while also attempting to evade analysis and disrupt defenders. ResokerRAT creates a mutex, checks for debuggers, relaunches with administrator rights, blocks tools including Task Manager and Process Hacker, weakens UAC-related settings, and adds itself to the Windows Run registry key for startup execution. Defenders were urged to monitor suspicious outbound Telegram API traffic, Run key persistence, restricted PowerShell activity, and user reports that security or system tools suddenly cannot be opened.

Share:
ResokerRAT Uses Telegram Bot API to Control and Persist on Windows Hosts
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 31, 20263mo ago

Media reports disclose ResokerRAT's Telegram-based C2 and evasion features

News coverage publicized ResokerRAT as a Windows RAT delivered as Resoker.exe that communicates with attackers through hardcoded Telegram bot credentials over HTTPS to api.telegram.org. Reports highlighted its persistence via the Run registry key, interference with tools such as Task Manager and Process Hacker, and recommendations for defenders to monitor suspicious Telegram API traffic and related host-based indicators.

Mar 30, 20263mo ago

K7 Security Labs publishes technical report on ResokerRAT

A technical report by K7 Security Labs researcher Priyadharshini documented a newly identified Windows remote access trojan called ResokerRAT. The report described its use of Telegram Bot API for command-and-control, along with capabilities including persistence, privilege escalation, anti-analysis, screenshot capture, keylogging, and downloading additional payloads.

Mar 12, 20263mo ago

Breakglass Intelligence publishes first public report on ResokerRAT

Breakglass Intelligence published an early technical analysis of a newly documented 64-bit Windows RAT called Resoker that used the Telegram Bot API as its sole command-and-control channel. The report detailed active bot infrastructure, capabilities such as screenshots, keylogging, persistence and UAC manipulation, and multiple OPSEC failures that made the malware straightforward to detect.

Resoker RAT: First Report on a Telegram-Controlled Trojan With Every OPSEC Failure in the Book - Breakglass Intelligence - Breakglass Intelligence
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
Malware
2 linked
Affected products
4 linked
WindowsWiresharkGithubProcess Explorer
Organizations
11 linked
TelegramK7 Security LabsGBHackers NewsGoogleLinkedinKasperskyXMicrosoft CorporationGitHubBreakglass IntelligenceMysten Labs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

ResokerRAT Uses Telegram Bot API to Control and Persist on Windows Hosts | Mallory