A Go backdoor analyzed by Netskope Threat Labs polls Telegram for operator instructions, runs selected commands through PowerShell, and sends results back in chat. Its documented command set also includes relaunch and self-deletion handlers. One important caveat: although it replies “Screenshot captured,” the sample’s screenshot feature is incomplete and does not establish that an image was taken.
Netskope Threat Labs published its technical analysis on February 14, 2025; SecurityWeek reported on it four days later. The behavior below describes the sample Netskope examined, not every Go backdoor or a confirmed large-scale campaign. Neither report establishes how many systems were affected or who operated the sample.
How the backdoor uses Telegram
The sample uses a Telegram bot token to create a bot instance with an open-source Go package, then polls for updates from a chat. It checks the incoming command’s length and content before routing it to one of its handlers. When it has a result or status message, it sends that message through the Telegram package’s Send function.
Netskope notes that using a familiar cloud application for command-and-control (C2) can make it harder for defenders to distinguish malicious API activity from legitimate use. The report mentions OneDrive, GitHub, and Dropbox as other services that could pose a similar challenge if abused; it does not say this sample used them.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
What each command does
| Command | Documented behavior in the analyzed sample |
|---|---|
/cmd |
Runs an operator-supplied PowerShell instruction and returns its output in Telegram. |
/persist |
Repeats the file-path check and relaunch logic for the expected location. |
/screenshot |
Replies “Screenshot captured,” but the screenshot feature is incomplete; the reply is not evidence that an image was captured. |
/selfdestruct |
Deletes C:WindowsTempsvchost.exe, terminates the process, and sends “Self-destruct initiated” to the Telegram chat. |
Running a PowerShell command
The /cmd handler uses two chat messages rather than one: the operator first sends /cmd, then sends the PowerShell instruction separately. After the first message, the malware sends “Enter the command:” in Russian. Netskope describes the execution form as powershell -WindowStyle Hidden -Command <command>; the command output is sent back through Telegram.
Relaunching from the expected path
During initialization, the sample’s installSelf function checks whether it is running as C:WindowsTempsvchost.exe. If not, it reads its own contents, writes a copy at that path, starts a process from the copy, and exits the original process. The /persist command invokes the relevant check-and-relaunch sequence again. This is file-path and process behavior, not documented registry-based persistence.
Screenshot and self-deletion responses
The screenshot handler is not fully implemented. Its “Screenshot captured” reply is only a response string; it should not be interpreted as confirmation that the backdoor took or transmitted a screenshot.
For /selfdestruct, Netskope reports that the sample deletes the expected executable path, terminates its process, and sends “Self-destruct initiated.” These actions describe the analyzed code and do not prove that the command was used on an infected system.
Rank #3
What defenders can take from the analysis
Netskope’s findings point to several behaviors that may merit investigation when they appear together. None alone proves infection, and these observations are not a complete detection rule:
- Unexpected Telegram Bot API activity from an endpoint, especially when associated with command polling and replies.
- A process running from
C:WindowsTempsvchost.exe, where the executable name and temporary-directory location should be assessed in context. - PowerShell launched with a hidden window and an operator-provided command.
- A pattern of Telegram messages that select a command, receive a prompt, then carry a command and its output.
Netskope lists Trojan.Generic.37477095 in its Threat Protection detection section. That is a vendor detection label, not a universal malware-family name or assurance that every security product detects the sample. Netskope points readers to a GitHub repository for indicators of compromise and scripts; its article does not provide a complete independent IOC set in the text.
Rank #4
What is known about the sample’s origin and reach
Netskope described the sample as apparently under development while noting that its implemented behaviors were functional. The researchers characterized a Russian origin as possible; SecurityWeek summarized the assessment as an apparent Russian developer based on a message string. That is an attributed, tentative inference—not confirmation of the developer’s nationality, the operator’s identity, or a threat group.
The two reports do not establish victim counts, infection rates, campaign scale, or successful real-world impact. Netskope author Leandro Fróes, a Senior Threat Research Engineer, wrote that cloud applications can be effective C2 channels partly because defenders may find it difficult to tell normal API use from C2 traffic. The available reporting supports that defensive concern, but not a broader claim about this sample’s prevalence.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
Telegram transport and the “sendEncrypted” name
Netskope says the malware sends messages through the Telegram package’s Send function, called by a malware function named sendEncrypted. The function name alone does not establish a separate encryption protocol for the malware’s Telegram traffic; the analysis does not substantiate encryption beyond Telegram’s own service behavior.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

