ResokerRAT turns Telegram into a stealth control channel for Windows attacks
VPN Central [Unofficial]
April 7, 2026
A newly documented Windows remote access trojan called ResokerRAT uses Telegram’s Bot API as its command-and-control channel, giving attackers a way to control infected systems without relying on a custom server. That matters because Telegram traffic can blend in with normal web activity, which can make the malware harder to flag quickly on corporate networks. […]
The post ResokerRAT turns Telegram into a stealth control channel for Windows attacks appeared first on VPN Central.
Discussion in the ATmosphere