Malware, Ransomware

Novel Skitnet malware grows traction among ransomware groups

Malware attack virus alert. Person use smartphone with virtual warning sign with ransomware word. warning notification, Cyber threats.

More ransomware gangs, including Black Basta and Cactus, have been leveraging the new Skitnet malware, also known as Bossnet, for covert post-exploitation operations since earlier this year, reports BleepingComputer.

Attacks involving Skitnet commence with the deployment and execution of a Rust-based loader enabling the decryption and in-memory loading of a ChaCha20-encrypted Nim binary, which creates a DNS-based reverse shell for command-and-control communications before triggering a trio of threads for heartbeat DNS request delivery, shell output tracking and exfiltration, and command listening and decryption activities, an analysis from PRODAFT revealed. Aside from supporting commands that enable persistence and screenshot capturing via PowerShell, Skitnet also allows stealthy installation of the AnyDesk and RUT-Serv remote access tools, triggers a PowerShell command loop, and performs antivirus and security software enumeration, as well as facilitates in-memory execution of PowerShell scripts for more customized intrusions, researchers added. All of Skitnet's indicators of compromise have already been published on PRODAFT's GitHub repository.

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds