Skitnet: The Stealth Malware Powering a New Wave of Ransomware Attacks

Listen to this Post

Featured Image

The Invisible Hand Behind Modern Cybercrime

A new stealth malware named Skitnet — nicknamed Bossnet in some underground communities — has quietly emerged as a rising star among ransomware gangs. Initially spotted in underground forums in April 2024, its use has skyrocketed in early 2025. Unlike traditional ransomware that encrypts data and demands a ransom, Skitnet operates behind the scenes, helping attackers maintain access and control over compromised networks without triggering alarms. Its technical sophistication and stealthy footprint make it a go-to tool for cybercriminals looking to stay under the radar while executing high-impact attacks.

Inside the Rise of Skitnet: 30-Line Digest

Skitnet is not your average piece of malware. Written with a Rust-based loader and powered by a Nim binary, it performs complex operations while remaining hidden from security tools. Once executed on a target system, the loader decrypts the payload using the ChaCha20 encryption algorithm and establishes a DNS-based reverse shell — an advanced method for communicating with its command and control (C2) server. By using randomized DNS queries, it minimizes detection risk and masks its presence on corporate networks.

The malware operates using three concurrent threads: one sends continuous DNS “heartbeat” requests to keep the connection alive, the second monitors outputs from the victim’s system and exfiltrates data, and the third decrypts and executes commands received via DNS responses.

Skitnet’s C2 control panel provides attackers with full situational awareness — they can view IP addresses, geolocations, machine statuses, and issue real-time commands. These include installing remote access tools like AnyDesk and RUT-Serv, capturing screenshots, initiating PowerShell shells for command execution, checking antivirus software, and even establishing persistence via DLL hijacking in startup folders.

More worrying is its modularity. Skitnet can be extended with a .NET loader, allowing hackers to execute PowerShell scripts directly in memory — a method that avoids writing files to disk and bypasses many traditional security layers.

Prodaft researchers observed Skitnet in real-world attacks, including campaigns from well-known ransomware groups like BlackBasta and Cactus. It’s become especially popular in phishing attacks involving Microsoft Teams — a trend that reflects the increasing exploitation of workplace collaboration tools.

While custom malware still dominates high-level ransomware operations, Skitnet represents a cost-effective, plug-and-play solution for smaller or less technically capable threat groups. Its availability on underground marketplaces like RAMP and its low barrier to use make it a growing threat in the cybersecurity landscape.

What Undercode Say:

Skitnet is a game-changer for threat actors, especially those balancing sophistication with stealth. This malware is a masterclass in post-exploitation strategy, enabling criminals to maintain access, extract information, and remotely control compromised systems with minimal footprint.

Unlike traditional malware that floods logs or leaves forensic trails, Skitnet thrives on invisibility. By leveraging DNS tunnels, memory-only execution, and common remote tools, it camouflages itself within the noise of enterprise environments. Its use of legitimate applications like AnyDesk and RUT-Serv also complicates detection, as these tools often appear on endpoints for legitimate IT purposes.

The inclusion of PowerShell-based capabilities showcases its adaptability. PowerShell is a double-edged sword in enterprise security — it’s a vital admin tool but also a favorite for attackers. Skitnet exploits this duality, using PowerShell for persistence, shell control, screenshotting, and in-memory execution of custom payloads.

One of the most dangerous aspects is its modular framework. This isn’t a one-size-fits-all malware — it evolves. The .NET loader allows attackers to expand their toolkit based on mission objectives. This modularity also means attribution becomes harder, as multiple threat groups using Skitnet can tweak its functions differently.

Furthermore, Skitnet’s popularity highlights a shift in the threat landscape: ransomware gangs are no longer relying exclusively on custom-built malware. Instead, they’re turning to proven, commercial-grade solutions available in underground forums. This democratizes access to powerful tools and lowers the entry barrier for new cybercriminal groups.

While top-tier APTs and ransomware actors still rely on bespoke exploits, Skitnet proves that “off-the-shelf” can be just as deadly when deployed smartly. For defenders, this signals a need to go beyond signature-based detection. Behavioral analytics, DNS traffic monitoring, and PowerShell auditing are no longer optional — they are essential.

Security teams must also scrutinize legitimate tools like AnyDesk. Their unauthorized presence on systems should trigger alerts and investigations. Likewise, monitoring startup folders for DLL hijacks and unusual shortcut behavior can serve as early warning signs.

Ultimately, Skitnet is a reminder that the line between commodity malware and advanced persistent threats is getting blurrier. As it becomes more widespread, we can expect to see it in everything from corporate espionage to extortion-based ransomware campaigns.

Fact Checker Results:

✅ Verified deployment of Skitnet by BlackBasta and Cactus
✅ Confirmed use of DNS tunneling and PowerShell scripting
✅ Skitnet is active on underground forums since April 2024

Prediction:

Skitnet is poised to become a staple in ransomware operations throughout 2025 and beyond. Its stealth, modular design, and low cost will likely attract even more cybercrime groups. Expect broader adoption in targeted attacks, especially those involving social engineering and remote collaboration tools like Teams and Zoom. Security teams must adapt now or risk falling behind in this new era of silent infiltration.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.linkedin.com
Wikipedia
Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram