GodRAT: A Stealthy RAT Targeting Financial Institutions Through Complex Malware Infrastructure
A newly observed Remote Access Trojan (RAT) campaign is targeting financial institutions, using stealth and social engineering to penetrate secure environments.

A newly observed Remote Access Trojan (RAT) campaign is targeting financial institutions, using stealth and social engineering to penetrate secure environments. At the core of this campaign is GodRAT, a modular and persistent threat leveraging multiple delivery methods and infrastructure layers.

Skype as an Infection Vector
One of the standout tactics in this campaign is the use of Skype Messenger as a delivery mechanism. Attackers compromise or spoof legitimate Skype accounts to send direct messages containing malicious .SCR and .PIF files, disguised as legitimate business documents, such as:
2024-08-01_2024-12-31Data.scr
Corporate customer transaction &volume.pif
2025TopClineData&1.scr
Once a user opens the file, the embedded payload silently installs GodRAT, enabling the attacker to establish remote control, steal credentials, and exfiltrate data, all without raising immediate suspicion.
This infection method is particularly dangerous because:
Skype messages are often trusted and bypass traditional email filters
.SCR and .PIF files can easily blend in with normal downloads
The RAT communicates with external C2 servers using encrypted channels
How We Mitigate These Threats
We help organizations:
- Identify hidden malware infrastructure
Monitor and block malicious domains and IPs in realtime
Trace lateral movement within networks
Detect RAT behavior even in obfuscated or packed executables
Harden systems against pluginbased persistence and credential harvesting
Indicators of Compromise (IOCs)
| MD5 Hash | Description |
|---|---|
| d09fd377d8566b9d7a5880649a0192b4 | GodRAT Shellcode Injector |
| e723258b75fee6fbd8095f0a2ae7e53c | GodRAT SFX Executable |
| 8008375eec7550d6d8e0eaf24389cf81 | GodRAT |
| 31385291c01bb25d635d098f91708905 | Chrome Password Stealer |
| 605f25606bb925d61ccc47f0150db674 | Async RAT Injector |
| 4ecd2cf02bdf19cdbc5507e85a32c657 | Async RAT |
File Paths
C:\Users\[username]\Downloads\2025TopClineData&1.scr
C:\Users\[username]\Downloads\Corporate customer transaction &volume.pif
C:\telegram desktop\Company self-media account application qualifications&.zip
%ALLUSERSPROFILE%\bugreport\360Safe2.exe
%LOCALAPPDATA%\bugreport\bugreport_.exe
Domains and IPs
| Type | Value | Description |
|---|---|---|
| IP | 103.237.92.191 | GodRAT C2 |
| IP | 118.107.46.174 | GodRAT C2 |
| Domain | wuwu6[.]cfd | AsyncRAT C2 |
| URL | https://holoohg.oss-cn-hongkong.aliyuncs[.]com/HG.txt | AsyncRAT Payload URL |
Protect Your Organization Now
Attacks like these are designed to stay hidden, exfiltrate data, and provide persistent access to your systems.
If you’re in the financial sector and aren’t monitoring for these IOCs, you’re already at risk.
Contact us to run a threat assessment or learn how we can map and neutralize hidden malware infrastructure targeting your organization.
Let me know if you’d like this turned into a PDF alert, visual dashboard, or executive report for clients.



