216.73.217.22

Gh0st RAT-based GodRAT attacks financial organizations

· Published 19/08/2025 16:07 · Modified 19/08/2025 21:20

Export JSON

Essential information

Published
19/08/2025 16:07
Modified
19/08/2025 21:20
Tags
2025-08-19 asyncrat awesomepuppet chrome password stealer financial sector gh0st rat godrat ms edge password stealer password-stealer skype steganography
Related entities
1 intrusion sets (apt), 19 techniques (mitre), 4 malware, 6 others

Description

A newly identified Remote Access Trojan named , based on the codebase, has been targeting financial firms since September 2024. The attackers distribute malicious .scr files via , using to embed shellcode in images. supports plugins and is used alongside browser password stealers and . The campaign, likely an evolution of the RAT connected to Winnti APT, remains active as of August 2025. Targets include organizations in Hong Kong, United Arab Emirates, Lebanon, Malaysia, and Jordan. The attackers employ various techniques to evade detection and maintain persistent access to compromised systems.

External references