Still use Skype at work? Bad news, hackers are targeting it with dangerous malware
- Criminals found using Skype to deliver images hiding malware
- Victims were mostly SMBs in the Middle East
- The malware is new, but seems to have distant relatives
Cybercriminals have been found using Skype messenger to deliver Remote Access Trojans (RAT) malware, compromising victim’s computers and opening the doors for devastating stage-two attacks.
Cybersecurity researchers at Kaspersky recently uncovered a previously unseen malware variant called GodRAT being distributed via malicious screensaver files, disguised as financial documents.
Unusually, the miscreants were delivering the malware to their victims via Skype messenger until March 2025, when they pivoted to other channels.
GodRAT malware being spread
First off, the hackers would share fake financial data in an image file. By using steganography, they would hide shellcode in the files which, when activated, downloads the GodRAT malware from a third-party server.
The RAT harvests operating system details, local hostname, malware process name and process ID, the user account associated with the malware process, installed antivirus software, and the presence of a capture driver.
After that, GodRAT can receive additional plugins, depending on the initial information shared with the attackers. These plugins can be file explorers, or password stealers.
In some cases, the crooks used GodRAT to deploy AsyncRAT, a secondary implant that granted them prolonged, if not permanent, access.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“GodRAT appears to be an evolution of AwesomePuppet, which was reported by Kaspersky in 2023 and is likely linked to the Winnti APT. Its distribution methods, rare command-line parameters, code similarities with Gh0st RAT, and shared artifacts – such as a distinctive fingerprint header – suggest a common origin,” said Saurabh Sharma, Security Researcher at Kaspersky GReAT.
“The discovery of GodRAT demonstrates how such long-known tools can remain relevant in today’s cybersecurity landscape,”
Kaspersky did not discuss the number of victims, or potential success rate of the campaign, but it did stress that the victims were mostly small and medium-sized businesses (SMB) in UAE, Hong Kong, Jordan, and Lebanon.
You might also like
Criminals found using Skype to deliver images hiding malware Victims were mostly SMBs in the Middle East The malware is new, but seems to have distant relatives Cybercriminals have been found using Skype messenger to deliver Remote Access Trojans (RAT) malware, compromising victim’s computers and opening the doors for devastating…
Recent Posts
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- NordVPN Coupons and Deals: 77% Off in June 2026
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023