HomeSecurityTriton RAT leverages Telegram for remote access

Triton RAT leverages Telegram for remote access

A sophisticated Python-based remote access tool (RAT) known as Tritonhas emerged as a serious threat, using Telegram as a command and control infrastructure.

See also: PJobRAT campaign targeted Taiwanese users

Triton RAT Telegram

This malware allows attackers to gain remote access and control over compromised systems, with a particular focus on collecting Roblox credentials and security cookies that can bypass two-factor authentication.

The RAT begins its operation by retrieving the Telegram Bot token and chat ID from Pastebin via Base64-encoded URLs, thus creating a secret communication channel.

Once deployed, the Triton RAT provides extensive system control capabilities, including logging keystrokes, stealing passwords, capturing screens, accessing the camera, and extracting data from the clipboard.

Cado Security researchers identified this threat while investigating a series of breaches, noting that the RAT's extensive feature set makes it particularly dangerous in targeted attacks.

Analysis revealed that the malware code contains functions that systematically extract stored credentials from various browsers and specifically targets Roblox security cookies (.ROBLOSECURITY) from Chrome, Brave, and Firefox profiles.

The infection exploits social engineering techniques to gain initial access, after which it collects extensive system information, including hardware specifications, network settings, and user account details.

See also: Microsoft warns of new StilachiRAT malware

All collected data is efficiently transmitted to the attacker via Telegram, allowing for real-time monitoring and control of the compromised system.

Triton RAT leverages Telegram for remote access

The Triton RAT demonstrates advanced persistence tactics by creating multiple components that work together to maintain access.

The malware creates a VBScript named “updateagent.vbs” that disables Windows Defender and creates scheduled tasks, while a separate BAT script “check.bat” retrieves a binary file named “ProtonDrive.exe” from DropBox.

This sub-payload is stored in a hidden folder structure at the path “C:\Users\user\AppData\Local\Programs\Proton\Drive” and is run with administrator privileges.

The Triton RAT additionally uses anti-analysis techniques, checking for blacklisted processes, including debugging tools and antivirus, demonstrating the intent of its creators to evade detection while maintaining permanent control over compromised systems.

See also: Desert Dexter infects 900 victims with AsyncRAT

The term “malicious Remote Access Tool” (RAT) refers to a type of malware that allows an attacker to gain remote access to a computer or system without the user’s permission. RATs are typically used to steal data, monitor users, or perform other malicious activities, such as spreading other types of malware. These tools typically operate in the background and can be very difficult to detect by traditional security tools. Attackers can take complete control of the infected system, gaining access to files, applications, and other information.

Source: cybersecuritynews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS