Hackers use Telegram-based ResokerRAT to spy on Windows PCs and keep access after reboot
VPN Central [Unofficial]
April 1, 2026
A newly analyzed Windows remote access trojan called ResokerRAT uses Telegram’s Bot API as its control channel instead of a traditional command-and-control server. That gives attackers a familiar cloud service to hide behind while they send commands and receive stolen data from infected systems. The malware runs as Resoker.exe and focuses on Windows systems. Researchers […]
The post Hackers use Telegram-based ResokerRAT to spy on Windows PCs and keep access after reboot appeared first on VPN Central.
Discussion in the ATmosphere