Gh0st RAT-based GodRAT attacks financial organizations
Essential information
- Published
- 19/08/2025 16:07
- Modified
- 19/08/2025 21:20
- Tags
- 2025-08-19 asyncrat awesomepuppet chrome password stealer financial sector gh0st rat godrat ms edge password stealer password-stealer skype steganography
- Related entities
- 1 intrusion sets (apt), 19 techniques (mitre), 4 malware, 6 others
Description
A newly identified Remote Access Trojan named GodRAT, based on the Gh0st RAT codebase, has been targeting financial firms since September 2024. The attackers distribute malicious .scr files via Skype, using steganography to embed shellcode in images. GodRAT supports plugins and is used alongside browser password stealers and AsyncRAT. The campaign, likely an evolution of the AwesomePuppet RAT connected to Winnti APT, remains active as of August 2025. Targets include organizations in Hong Kong, United Arab Emirates, Lebanon, Malaysia, and Jordan. The attackers employ various techniques to evade detection and maintain persistent access to compromised systems.