Home » Skitnet malware: The new ransomware favorite

Skitnet malware: The new ransomware favorite

by Wikdaily
0 comments
Hacker with malware code in computer screen. Cybersecurity, privacy or cyber attack. Programmer or fraud criminal writing virus software. Online firewall and privacy crime. Web data engineer.


“The author (of the malware) sells both the server code and the malware itself,” researchers added. “The server automatically wipes SSH connection logs, IP addresses, command history logs, and cache, to avoid leaving any traces that could be used in forensic investigation.”

Additional commands for remote access

Skitnet also has commands to quietly install and launch signed versions of remote desktop tools like AnyDesk or RUT, allowing attackers to gain remote access to infected systems.

“The inclusion of remote access capabilities via AnyDesk and RUT-Serv, along with commands for data exfiltration and security product enumeration, highlights the malware’s versatility,” researchers said. Skitnet’s persistence mechanisms, including DLL hijacking and PowerShell-based execution, ensure that it remains active on compromised systems.”

You may also like

Leave a Comment

Welcome to WikDaily, your trusted source for the latest news, trends, and insights across the globe. We are a dynamic blog-style news platform committed to delivering fast, accurate, and engaging content across a variety of topics—from breaking headlines to deep dives into tech, business, entertainment, travel, sports, and more.

Edtior's Picks

Latest Articles