New GodRAT trojan targets financial sector via Skype

New GodRAT trojan targets financial sector via Skype

A new remote access Trojan (RAT) called GodRAT has been found targeting financial institutions, with its initial distribution channel being malicious screensaver files sent via Skype messenger, cybersecurity firm Kaspersky has revealed.

The Kaspersky Global Research and Analysis Team (GReAT) discovered the malware after it was uploaded to an online scanner in July 2024. The threat actors behind the campaign targeted small and medium-sized businesses (SMBs) in the United Arab Emirates, Hong Kong, Jordan and Lebanon.

GodRAT is highly evasive, using steganography – the practice of concealing a file within another – to hide malicious code within image files to avoid detection. The RAT then steals system information and can use additional plugins to explore victims’ systems and deploy password stealers to extract credentials from browsers like Chrome and Microsoft Edge. The attackers also used AsyncRAT as a secondary implant to ensure continued access to compromised systems.

Saurabh Sharma, a security researcher for Kaspersky’s GReAT, said, “GodRAT appears to be an evolution of AwesomePuppet, which was reported by Kaspersky in 2023 and is likely linked to the Winnti APT.” Sharma noted that the malware’s code has similarities to the two-decade-old Gh0st RAT, highlighting how threat actors continue to adapt legacy codebases for new campaigns.

The GodRAT builder allows attackers to disguise the payload by using legitimate process names and saving the file in various formats, including .exe, .com and .bat.

Browse our latest issue

Intelligent Fin.tech

View Magazine Archive