A recent effort targets financial institutions, such as trading and brokerage firms, by distributing GodRAT, a remote access trojan that has not been previously identified.
In a technical study released today, Kaspersky researcher Saurabh Sharma said that the malicious activity entails the “distribution of malicious.SCR (screen saver) files disguised as financial documents via Skype messenger.”
The assaults use a method known as steganography to hide the shellcode needed to download the malware from a command-and-control (C2) server within image files. They have been active as recently as August 12, 2025. Since September 9, 2024, the screen saver artifacts have been identified, focusing on nations and territories such as Hong Kong, the United Arab Emirates, Malaysia, Jordan, and Lebanon.
GodRAT, which is thought to be based on Gh0st RAT, enhances its capability by using plugins to deliver secondary payloads like AsyncRAT read more about New GodRAT Trojan Targets Trading Firms Using Steganography and Gh0st RAT Code.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
