GodRAT – New RAT targeting financial institutions
ID: 379b7206-ced1-5334-936f-7dd2a6820bb9
STIX ID: report--379b7206-ced1-5334-936f-7dd2a6820bb9
Feed Name: Securelist by Kaspersky
Kaspersky-style technical analysis of an active campaign (detected through 2025-08-12) targeting financial/trading firms via malicious .scr and .pif attachments delivered over Skype. Attackers used steganography to hide shellcode in images which loads GodRAT (a Gh0st RAT derivative) and also deployed AsyncRAT and browser password stealers via a FileManager plugin; the report includes detailed behaviors, persistence mechanisms, C2 protocols, builder/source discovery, and extensive IOCs (file hashes, paths, IPs/domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
