Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » The new Godratotrojan is targeting trading companies using steganography and GH0st rat code
Celebrities

The new Godratotrojan is targeting trading companies using steganography and GH0st rat code

By August 19, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

August 19, 2025Ravi LakshmananMalware/Cyber Attacks

Steganography and GH0st rat code

Financial institutions such as trading and brokerage companies are the targets of new campaigns offering previously unreported remote access trojans called Godrat.

Malicious activities include “distribution of malicious .SCR (screensaver) files disguised into financial documents via Skype Messenger.”

The attack, which became active on August 12, 2025, employs a technique called Steganography to hide it within the image file shellcode used to download malware from a command and control (C2) server. Screensaver artifacts have been detected since September 9, 2024 and are targeting countries and territories such as Hong Kong, the United Arab Emirates, Lebanon, Malaysia and Jordan.

GoDrat is rated as being based on GH0st rats and follows a plugin-based approach that enhances functionality to harvest sensitive information and provide secondary payloads like Asyncrat. It is worth mentioning that Gh0st rats publicly leaked their source code in 2008 and have since been adopted by various Chinese hacking groups.

Cybersecurity

The Russian cybersecurity company said the malware is another GH0st rat-based backdoor evolution known as Awesome Puppet, first documented in 2023, and is considered to be the handiwork of prolific Chinese threat actor Winnti (aka APT41).

Screen Saver files act as self-extracting executables that incorporate a variety of embedded files, including secondary DLLs by legitimate executables. The DLL extracts the hidden shellcode within the .jpg image file, paving the way for Godrat to unfold.

The Trojan establishes communication with the C2 server over TCP, gathers system information, and pulls out a list of antivirus software installed on the host. The captured details are sent to the C2 server, and the server then responds with a follow-up procedure that allows it –

Insert the received plugin into memory to close the socket and terminate the rat process.

One plugin downloaded by the malware is a FileManager DLL that allows you to enumerate file systems, perform file operations, perform open folders, and perform searches for files at specified locations. This plugin is also used to deliver additional payloads, such as Google Chrome, Microsoft Edge browsers and password steelers for Asyncrat Trojan.

Kaspersky said it discovered the complete source code for the Godrat client and builder that was uploaded to the Virustotal Online Malware scanner in late July 2024. The builder can be used to generate either an executable or an A DLL.

Identity Security Risk Assessment

When the executable option is selected, the user chooses to select the legitimate binaries from the list where malicious code is injected into svchost.exe, cmd.exe, cscript.exe, curl.exe, wscript.exe, qqmusic.exe and qqsclauncher.exe. The final payload can be saved in one of the following file types: .exe, .com, .bat, .scr, and .pif.

“Older implant codebases such as GH0st rats from nearly 20 years ago continue to be used today,” Kaspersky says. “These are often customized and rebuilt to target a wide range of victims.”

“These older implants are known to have been used for a long time by a variety of threat actors, and Godrat’s findings show that legacy codebases like the GH0st rats can still maintain long lifespans in cybersecurity landscapes.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleUS spy chief says the UK has removed demand for apple backdoors
Next Article Aalo Atomics raises $100 million to build microreactors and data centers together

Related Posts

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

BTS’s “Come Over” was chosen as this week’s best new song

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

Far from the pitch, David Beckham remains soccer’s biggest star

Cardi B, Fat Joe and other musicians react

Trending Posts

BTS’s “Come Over” was chosen as this week’s best new song

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026

Cardi B, Fat Joe and other musicians react

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.