Ransomware gangs increasingly use Skitnet post-exploitation malware
A new malware known as Skitnet ("Bossnet") is being used more and more by ransomware gang members to carry out covert post-exploitation operations on compromised networks.
Although the virus has been available for purchase on underground platforms such as RAMP since April 2024, Prodaft researchers claim that it began to become increasingly popular with ransomware gangs in early 2025.
Prodaft informed BleepingComputer that they have seen several ransomware operations use Skitnet in actual assaults, such as Cactus and BlackBasta in Microsoft Teams phishing attempts against the company.
A Rust-based loader that decrypts a ChaCha20 encrypted Nim binary and loads it into RAM is dumped and run on the target system to initiate the Skitnet infection read more about Ransomware gangs incre...

