HomeSecurityRansomware gangs use Skitnet malware

Ransomware gangs use Skitnet malware

A new malware, known as Skitnet or “Bossnet” , is gaining ground on dark web cybercrime forums, with more and more ransomware gangs adopting it to enhance their operations on already compromised networks . Skitnet has been for sale since April 2024 on the underground forum RAMP . However, according to Prodaft , ransomware gangs have been using it since early 2025.

Ransomware gangs use Skitnet malware

Prodaft reports that the malware has been exploited in attacks by well-known groups, such as BlackBasta and Cactus.

How Skitnet malware works

Systems are infected with Skitnet via a Rust-based loader, which installs itself on the target, decrypts a ChaCha20 encrypted Nim binary , and loads it into memory.

See also: Phishing emails distribute Horabot malware in Latin America

Once activated, the Nim payload installs a DNS-based reverse shell, allowing silent communication with the command and control (C2) server. It uses deceptive, random DNS queries.

The malware starts three threads to:

  • sending heartbeat DNS requests
  • monitoring and exporting shell output
  • listening and decrypting commands from DNS responses

Commands and settings are transferred either via DNS or HTTP, based on commands issued through the Skitnet C2 control panel. The C2 panel offers attackers information such as IP addresses, target location, connection status , and the ability to remotely execute commands.

Skitnet malware commands: Full remote control

The Skitnet malware is accompanied by a powerful repertoire of commands that provide cybercriminals with complete control over compromised systems , with an emphasis on discreet presence and constant communication with command and control (C2) servers

See also: ClickFix: COLDRIVER hackers distribute LOSTKEYS malware

Basic functions of Skitnet

  • startup : Creates persistence on the system by downloading three files—including a malicious DLL—and creates a shortcut to a legitimate Asus executable (ISP.exe) in the Startup folder. This triggers the DLL hijacking to execute a PowerShell script (pas.ps1) and maintain a connection to the C2.
  • Screen: Takes screenshots of the user's screen via PowerShell, uploads them to Imgur , and returns the image URL to the control server, providing attackers with a view of what is happening on the victim's desktop.
  • Anydesk: Silently downloads and installs the application AnyDesk, a well-known remote access tool. The window and system icon remain hidden to avoid detection.
  • Rutserv: Uses the same approach to install RUT-Serv, another legitimate remote control tool, which silently integrates into the target system.
  • Shell: Starts a PowerShell command loop. It sends an initial message “Shell started..”, then repeatedly contacts the server for new commands, which it executes using Invoke-Expression. Finally, it sends the results back.
  • AV: Scans the system for antivirus software, sending back information about the type and status of installed protection.

Extra weapon: .NET loader for in-memory execution

In addition to pre-installed commands, Skitnet also includes a .NET loader, giving attackers the ability to dynamically load and execute PowerShell scripts directly into the computer's memory, avoiding disk logging and enhancing the stealth of the attack.

With its increasing use by ransomware organizations, Skitnet malware is not just a post-exploitation tool, but a complete platform remote surveillance and control, designed to remain invisible and highly effective.

Traditionally, ransomware groups prefer to develop custom tools tailored to their operational goals, ensuring low detection by security software. However, creating such solutions is time-consuming, expensive, and requires highly skilled developers – resources that are not always available, especially for less organized criminal groups.

See also: Fake Discord PyPI Package contains malware

Skitnet malware ransomware

Skitnet , a ready-to -use malware distributed on underground forums, fills this gap , offering powerful features at a low cost and immediate availability. Using off-the-shelf malware like Skitnet drastically reduces development time and makes it harder to track down perpetrators, as it can be used by multiple threat actors simultaneously.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The Prodaft has already published relevant indicators of compromise (IoCs) on GitHub, giving security experts tools to identify and analyze Skitnet activity in the field.

Malware protection

  • Educating users about social engineering tactics and phishing attacks
  • Install (and update) antivirus and anti-malware software on all endpoints
  • Implement powerful email filters to block phishing emails and malicious attachments
  • Use of firewalls and intrusion detection/prevention systems (IDS/IPS)
  • Network segmentation to limit the spread of malware
  • Implementation of the principle of least privilege (PoLP), so that users only have access to necessary resources
  • Multi-factor authentication (MFA) implementation
  • Updating operating systems, software and applications
  • Encryption of sensitive data
  • Continuous monitoring and analysis of system and network logs
  • Back  up important  data

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS