External Publication
Visit Post

Hackers use Telegram-based ResokerRAT to spy on Windows PCs and keep access after reboot

VPN Central [Unofficial] April 1, 2026
Source
A newly analyzed Windows remote access trojan called ResokerRAT uses Telegram’s Bot API as its control channel instead of a traditional command-and-control server. That gives attackers a familiar cloud service to hide behind while they send commands and receive stolen data from infected systems. The malware runs as Resoker.exe and focuses on Windows systems. Researchers […] The post Hackers use Telegram-based ResokerRAT to spy on Windows PCs and keep access after reboot appeared first on VPN Central.

Discussion in the ATmosphere

Loading comments...