Alpha Cyber

GodRAT: A Stealthy RAT Targeting Financial Institutions Through Complex Malware Infrastructure

A newly observed Remote Access Trojan (RAT) campaign is targeting financial institutions, using stealth and social engineering to penetrate secure environments.

Alpha Cyber Research2 min readupdated 1 Apr 2026
Godrat Image

A newly observed Remote Access Trojan (RAT) campaign is targeting financial institutions, using stealth and social engineering to penetrate secure environments. At the core of this campaign is GodRAT, a modular and persistent threat leveraging multiple delivery methods and infrastructure layers.

GodRat Graph

Skype as an Infection Vector

One of the standout tactics in this campaign is the use of Skype Messenger as a delivery mechanism. Attackers compromise or spoof legitimate Skype accounts to send direct messages containing malicious .SCR and .PIF files, disguised as legitimate business documents, such as:

2024-08-01_2024-12-31Data.scr

Corporate customer transaction &volume.pif

2025TopClineData&1.scr

Once a user opens the file, the embedded payload silently installs GodRAT, enabling the attacker to establish remote control, steal credentials, and exfiltrate data, all without raising immediate suspicion.

This infection method is particularly dangerous because:

Skype messages are often trusted and bypass traditional email filters

.SCR and .PIF files can easily blend in with normal downloads

The RAT communicates with external C2 servers using encrypted channels

How We Mitigate These Threats

We help organizations:

  • Identify hidden malware infrastructure
    Monitor and block malicious domains and IPs in realtime
    Trace lateral movement within networks
    Detect RAT behavior even in obfuscated or packed executables
    Harden systems against pluginbased persistence and credential harvesting

Indicators of Compromise (IOCs)

MD5 HashDescription
d09fd377d8566b9d7a5880649a0192b4GodRAT Shellcode Injector
e723258b75fee6fbd8095f0a2ae7e53cGodRAT SFX Executable
8008375eec7550d6d8e0eaf24389cf81GodRAT
31385291c01bb25d635d098f91708905Chrome Password Stealer
605f25606bb925d61ccc47f0150db674Async RAT Injector
4ecd2cf02bdf19cdbc5507e85a32c657Async RAT

File Paths

C:\Users\[username]\Downloads\2025TopClineData&1.scr
C:\Users\[username]\Downloads\Corporate customer transaction &volume.pif
C:\telegram desktop\Company self-media account application qualifications&.zip
%ALLUSERSPROFILE%\bugreport\360Safe2.exe
%LOCALAPPDATA%\bugreport\bugreport_.exe

Domains and IPs

TypeValueDescription
IP103.237.92.191GodRAT C2
IP118.107.46.174GodRAT C2
Domainwuwu6[.]cfdAsyncRAT C2
URLhttps://holoohg.oss-cn-hongkong.aliyuncs[.]com/HG.txtAsyncRAT Payload URL

Protect Your Organization Now

Attacks like these are designed to stay hidden, exfiltrate data, and provide persistent access to your systems.

If you’re in the financial sector and aren’t monitoring for these IOCs, you’re already at risk.
Contact us to run a threat assessment or learn how we can map and neutralize hidden malware infrastructure targeting your organization.

Let me know if you’d like this turned into a PDF alert, visual dashboard, or executive report for clients.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]