HomeSecurityZynorRAT targets Windows and Linux systems

ZynorRAT targets Windows and Linux systems

A new sophisticated remote access trojan, dubbed ZynorRAT, has emerged as a cross-platform threat, targeting both systems Windows and Linux.

ZynorRAT targets Windows and Linux systems

The malware was first discovered in July 2025 and is written in Go. It represents a significant advancement in remote access capabilities, combining traditional RAT functionality with modern communication channels to evade detection and maintain persistent access to compromised systems.

The malware demonstrates remarkable flexibility in its attack methodology, using Telegram bots as the primary means of communication between infected machines and malicious actors. This approach allows attackers to issue commands, extract data , and monitor victims’ systems via encrypted messaging channels that blend seamlessly with regular traffic.

The use of popular messaging platforms for malicious purposes reflects the evolving cyberthreat landscape, where traditional network monitoring may fail to detect suspicious communications.

See also: Docker malware targets exposed APIs

ZynorRAT's cross-platform design allows malicious actors to compromise a variety of environments, from enterprise Linux servers to Windows workstations, creating a single attack surface across heterogeneous networks.

Sysdig researchers discovered the malware during threat hunting exercises.

Information gathered from Telegram channels suggests that ZynorRAT was likely developed by Turkish-speaking actors, with evidence pointing to a single developer known by the alias “halil,” who may be preparing the tool for commercial distribution on underground markets.

ZynorRAT targets Windows and Linux systems

ZynorRAT malware: How it works

ZynorRAT employs sophisticated persistence techniques that vary depending on the target platform. This demonstrates that the developer has a thorough understanding of system administration practices across different operating systems. On Linux systems, the malware exploits systemd user services via a carefully crafted service definition file placed in ~/.config/systemd/user/system-audio-manager[.]service. This approach leverages service administration capabilities that often escape detection by traditional security tools.

See also: Fake Madgicx Plus and SocialMetrics extensions steal Meta accounts

The persistence mechanism automatically restarts the malware process every 10 seconds if it is terminated, ensuring continuous access to compromised systems. Command execution capabilities extend beyond simple shell access, incorporating file system enumeration via /fs_list commands, process management via /proc_list and /proc_kill functions, and comprehensive system profiling via the /metrics command that collects the computer name, user information, and external IP addresses by querying api.ipify.org.

These capabilities turn infected machines into complete intelligence gathering platforms, providing attackers with detailed environmental awareness, which is essential for lateral movement and data extraction operations.

ZynorRAT targets Windows and Linux systems

General RAT malware protection tips

The first and most important way to protect against RAT malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks, as well as the ability to detect and remove RATs.

Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect  computer from the latest known trojans (e.g. ZynorRAT).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New phishing attack mimics Google AppSheet

You should also be careful with emails and messages you receive. Many RAT malware are spread through phishing attacks, so avoid opening attachments or clicking links from unknown sources.

Using strong passwords and changing them regularly can also help protect against attacks (e.g. ZynorRAT). Also, using two-factor authentication can add an extra layer of security.

Finally, information security training can be particularly useful. Understanding the ways in which RAT malware invades system and how to protect against them can help you stay safe.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS