Executive Summary
In late 2024, a targeted campaign leveraged a new remote access trojan, GodRAT, to infiltrate trading and brokerage firms across Hong Kong, the UAE, and other countries. Attackers, likely linked to the Winnti APT group, distributed malicious .scr and .pif files disguised as financial documents via Skype. These files deployed GodRAT—an evolved variant of Gh0st RAT—using innovative techniques like steganography to evade detection. Once inside victim networks, the campaign used file management plugins and browser password stealers to exfiltrate sensitive credentials, while also deploying secondary implants such as AsyncRAT for persistent control.
This ongoing incident highlights both the durability of legacy RAT codebases and the adaptability of threat actors employing advanced delivery and evasion tactics. It reflects a wider trend where financial institutions face persistent threats from intelligent, identity- and credential-focused attacks using proven malware frameworks.
Why This Matters Now
The GodRAT campaign underscores the urgency for financial institutions to modernize detection, segmentation, and east-west security to combat sophisticated, multi-stage threats leveraging both legacy malware and innovative evasive delivery. The continued evolution and deployment of Gh0st-based RATs signal ongoing risks as attackers exploit old but resilient tools in creative ways.
Attack Path Analysis
The attackers initiated their campaign by distributing weaponized .scr and .pif files via Skype, luring financial sector employees to execute the initial payload. Execution of these files leveraged steganography to deliver shellcode that injected GodRAT, which established persistence and enabled credential harvesting through deployment of plugins and additional RAT implants. Although privilege escalation was not explicitly documented, the malware sought elevated functionality through process injection and registry persistence mechanisms. After foothold, GodRAT and AsyncRAT allowed the attackers to perform reconnaissance and potentially move laterally within the network, accessing sensitive files and credentials. Command and control was maintained through encrypted TCP communications with remote C2 infrastructure. Sensitive browser credential data and other collected information were exfiltrated to attacker-controlled destinations. While public destructive impact was not observed, compromise of credentials and remote access posed significant risks to business integrity and operational continuity.
Kill Chain Progression
Initial Compromise
Description
Users were lured via phishing messages on Skype to download and execute malicious .scr/.pif files disguised as financial documents, leading to GodRAT shellcode execution through steganography.
Related CVEs
CVE-2024-4577
CVSS 9.8A vulnerability in PHP allows remote attackers to execute arbitrary code via argument injection, leading to potential system compromise.
Affected Products:
PHP PHP – < 8.1.17
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Process Injection: Dynamic-link Library Injection
Obfuscated Files or Information: Steganography
Boot or Logon Autostart Execution: Registry Run Keys/Startup Folder
Exfiltration Over C2 Channel
OS Credential Dumping: LSASS Memory
Input Capture: Keylogging
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users and Administrators
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management - Detection and Monitoring
Control ID: Art. 9(2)
CISA Zero Trust Maturity Model 2.0 – Account Monitoring and Threat Detection
Control ID: Identity Pillar - Visibility and Analytics
NIS2 Directive – Technical and Organizational Measures for Risk Management
Control ID: Art. 21(2)
GLBA (Gramm-Leach-Bliley Act) Safeguards Rule – Implement Access Controls and Monitoring
Control ID: 16 CFR 314.4(b)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target of GodRAT campaign with credential theft, lateral movement vulnerabilities, and compliance risks across PCI, NIST frameworks requiring enhanced segmentation.
Financial Services
Trading and brokerage firms specifically targeted via Skype distribution, facing password theft, east-west traffic infiltration, and regulatory compliance violations.
Capital Markets/Hedge Fund/Private Equity
High-value targets vulnerable to steganography-based attacks, browser credential harvesting, and multi-stage RAT deployments compromising sensitive financial data and transactions.
Investment Banking/Venture
Exposed to sophisticated social engineering via financial document lures, requiring enhanced egress filtering, threat detection, and zero trust segmentation controls.
Sources
- GodRAT – New RAT targeting financial institutionshttps://securelist.com/godrat/117119/Verified
- Kaspersky detected a new remote access trojan targeting financial institutions through Skype messengerhttps://www.kaspersky.com/about/press-releases/kaspersky-detected-a-new-remote-access-trojan-targeting-financial-institutions-through-skype-messengerVerified
- Anomali Cyber Watch: Noodlophile Stealer, GodRAT, Apple ImageIO Zero-Day, and Morehttps://www.anomali.com/blog/anomali-cyber-watch-noodlophile-stealer-godrat-apple-imageio-zero-dayVerified
- Chinese malware is flooding GitHub pages - HiddenGh0st, Winos and kkRAT hit devs via SEO poisoninghttps://www.techradar.com/pro/security/chinese-malware-is-flooding-github-pages-hiddengh0st-winos-and-kkrat-hit-devs-via-seo-poisoningVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive CNSF deployment—with controls like Zero Trust Segmentation, Egress Policy Enforcement, and Threat Detection—would have significantly limited attacker movement, contained the breach, and blocked data exfiltration, reducing dwell time and business risk.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection and alerting on suspicious new executables and anomalous binary transfers.
Control: Zero Trust Segmentation
Mitigation: Restricted workload privileges and process isolation to impede unauthorized elevation and persistence.
Control: East-West Traffic Security
Mitigation: Blocked unauthorized lateral network traffic and internal data access.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented or detected unauthorized outbound C2 communications.
Control: Encrypted Traffic (HPE)
Mitigation: Detected or blocked unauthorized data transfers leaving protected environments.
Accelerated visibility and incident response, curtailing business risk.
Impact at a Glance
Affected Business Functions
- Trading Operations
- Client Data Management
- Financial Transactions
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive client financial data, including account details and transaction histories.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation and robust east-west policy enforcement to prevent lateral movement and credential theft.
- • Apply egress controls and outbound filtering to block unauthorized communications and C2 connections from cloud or hybrid environments.
- • Operationalize behavioral Threat Detection & Anomaly Response systems to detect suspicious payload execution and process injections.
- • Enforce encrypted traffic inspection for visibility and prevention of covert data exfiltration channels targeting sensitive workloads.
- • Centralize multicloud visibility and incident response actions to minimize dwell time and reduce long-term business impact.



