Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Go backdoor analyzed by Netskope Threat Labs polls Telegram for operator instructions, runs selected commands through PowerShell, and sends results back in chat. Its documented command set also includes relaunch and self-deletion handlers. One important caveat: although it replies “Screenshot captured,” the sample’s screenshot feature is incomplete and does not establish that an image was taken.

Netskope Threat Labs published its technical analysis on February 14, 2025; SecurityWeek reported on it four days later. The behavior below describes the sample Netskope examined, not every Go backdoor or a confirmed large-scale campaign. Neither report establishes how many systems were affected or who operated the sample.

How the backdoor uses Telegram

The sample uses a Telegram bot token to create a bot instance with an open-source Go package, then polls for updates from a chat. It checks the incoming command’s length and content before routing it to one of its handlers. When it has a result or status message, it sends that message through the Telegram package’s Send function.

Netskope notes that using a familiar cloud application for command-and-control (C2) can make it harder for defenders to distinguish malicious API activity from legitimate use. The report mentions OneDrive, GitHub, and Dropbox as other services that could pose a similar challenge if abused; it does not say this sample used them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What each command does

Command Documented behavior in the analyzed sample
/cmd Runs an operator-supplied PowerShell instruction and returns its output in Telegram.
/persist Repeats the file-path check and relaunch logic for the expected location.
/screenshot Replies “Screenshot captured,” but the screenshot feature is incomplete; the reply is not evidence that an image was captured.
/selfdestruct Deletes C:WindowsTempsvchost.exe, terminates the process, and sends “Self-destruct initiated” to the Telegram chat.

Running a PowerShell command

The /cmd handler uses two chat messages rather than one: the operator first sends /cmd, then sends the PowerShell instruction separately. After the first message, the malware sends “Enter the command:” in Russian. Netskope describes the execution form as powershell -WindowStyle Hidden -Command <command>; the command output is sent back through Telegram.

Relaunching from the expected path

During initialization, the sample’s installSelf function checks whether it is running as C:WindowsTempsvchost.exe. If not, it reads its own contents, writes a copy at that path, starts a process from the copy, and exits the original process. The /persist command invokes the relevant check-and-relaunch sequence again. This is file-path and process behavior, not documented registry-based persistence.

Screenshot and self-deletion responses

The screenshot handler is not fully implemented. Its “Screenshot captured” reply is only a response string; it should not be interpreted as confirmation that the backdoor took or transmitted a screenshot.

For /selfdestruct, Netskope reports that the sample deletes the expected executable path, terminates its process, and sends “Self-destruct initiated.” These actions describe the analyzed code and do not prove that the command was used on an infected system.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What defenders can take from the analysis

Netskope’s findings point to several behaviors that may merit investigation when they appear together. None alone proves infection, and these observations are not a complete detection rule:

  • Unexpected Telegram Bot API activity from an endpoint, especially when associated with command polling and replies.
  • A process running from C:WindowsTempsvchost.exe, where the executable name and temporary-directory location should be assessed in context.
  • PowerShell launched with a hidden window and an operator-provided command.
  • A pattern of Telegram messages that select a command, receive a prompt, then carry a command and its output.

Netskope lists Trojan.Generic.37477095 in its Threat Protection detection section. That is a vendor detection label, not a universal malware-family name or assurance that every security product detects the sample. Netskope points readers to a GitHub repository for indicators of compromise and scripts; its article does not provide a complete independent IOC set in the text.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about the sample’s origin and reach

Netskope described the sample as apparently under development while noting that its implemented behaviors were functional. The researchers characterized a Russian origin as possible; SecurityWeek summarized the assessment as an apparent Russian developer based on a message string. That is an attributed, tentative inference—not confirmation of the developer’s nationality, the operator’s identity, or a threat group.

The two reports do not establish victim counts, infection rates, campaign scale, or successful real-world impact. Netskope author Leandro Fróes, a Senior Threat Research Engineer, wrote that cloud applications can be effective C2 channels partly because defenders may find it difficult to tell normal API use from C2 traffic. The available reporting supports that defensive concern, but not a broader claim about this sample’s prevalence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Telegram transport and the “sendEncrypted” name

Netskope says the malware sends messages through the Telegram package’s Send function, called by a malware function named sendEncrypted. The function name alone does not establish a separate encryption protocol for the malware’s Telegram traffic; the analysis does not substantiate encryption beyond Telegram’s own service behavior.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.