Click to chat
  • Solutions
    • Solutions
    • Artificial Intelligence
    • Data Analytics
    • Epicor for Distribution
    • Epicor for Manufacturing
    • IT Support
    • Managed Services
    • Microsoft 365
    • Microsoft Azure
    • Microsoft Licensing Support
    • Security
  • Innovation
    • Innovation
    • AI for Epicor
    • Cybersecurity
    • Data Analytics
    • Epicor in Azure
    • Epicor Kinetic ERP
    • Microsoft 365
    • Microsoft Azure
    • SaaS
  • Helpdesk
  • Resources
    • Resources
      • Resources
      • 2W Conversations
      • News Releases
      • Product Demo’s
      • Quick Tech Talks
      • Webinars
    • Blogs
  • About 2W
    • About Us
    • Contact Us
    • IT News
  • Join the Team
  • Client Login
  • Solutions
    • Solutions
    • Artificial Intelligence
    • Data Analytics
    • Epicor for Distribution
    • Epicor for Manufacturing
    • IT Support
    • Managed Services
    • Microsoft 365
    • Microsoft Azure
    • Microsoft Licensing Support
    • Security
  • Innovation
    • Innovation
    • AI for Epicor
    • Cybersecurity
    • Data Analytics
    • Epicor in Azure
    • Epicor Kinetic ERP
    • Microsoft 365
    • Microsoft Azure
    • SaaS
  • Helpdesk
  • Resources
    • Resources
      • Resources
      • 2W Conversations
      • News Releases
      • Product Demo’s
      • Quick Tech Talks
      • Webinars
    • Blogs
  • About 2W
    • About Us
    • Contact Us
    • IT News
  • Join the Team
  • Client Login
Contact Us
Home / IT News / Skitnet (“Bossnet”): The Stealthy Malware Powering Ransomware Operations

Skitnet (“Bossnet”): The Stealthy Malware Powering Ransomware Operations

05/16/25
Categories:
  • BlackBasta
  • Cactus
  • Cybersecurity
  • Malware
  • Ransomware
  • Skitnet

Cybersecurity professionals are facing a new challenge in the form of Skitnet, also known as Bossnet, a sophisticated malware that has rapidly gained traction among ransomware groups. First appearing on underground forums in April 2024, Skitnet has evolved into a powerful post-exploitation tool, allowing attackers to maintain persistence, evade detection, and execute commands remotely.

Skitnet operates through a multi-stage infection process, leveraging a combination of Rust, Nim, .NET, and PowerShell to infiltrate systems. The attack begins with a Rust-based loader, which decrypts and loads a ChaCha20-encrypted Nim binary directly into memory, avoiding traditional detection methods.

Once active, Skitnet establishes a DNS-based reverse shell, enabling covert communication with its command and control (C2) server. This allows attackers to issue commands, monitor system activity, and exfiltrate data, while remaining undetected.

Skitnet provides ransomware operators with a range of functionalities, including:

  • Persistence Mechanism: Establishes long-term access by exploiting DLL hijacking and PowerShell scripting.
  • Remote Access Tools: Silently install AnyDesk and RUT-Serv for remote control.
  • System Surveillance: Captures screenshots and uploads them to Imgur for attacker review.
  • Antivirus Enumeration: Identifies installed security software to evade detection.
  • PowerShell Command Execution: Runs arbitrary commands via Invoke-Expression, allowing attackers to manipulate the system.

Unlike custom-built malware, Skitnet is readily available on underground forums, making it an attractive option for cybercriminals. Its stealth capabilities, low detection rates, and ease of deployment allow attackers to infiltrate networks efficiently while minimizing forensic traces.

Security researchers have observed BlackBasta and Cactus ransomware groups deploying Skitnet in Microsoft Teams phishing attacks, demonstrating their effectiveness in real-world cyberattacks.

To defend against Skitnet, organizations should implement robust cybersecurity measures, including:

  • DNS Traffic Monitoring: Detect unusual DNS queries that may indicate malware communication.
  • Endpoint Detection & Response (EDR): Identify suspicious activity related to Rust and Nim-based payloads.
  • PowerShell Restrictions: Limit execution privileges to prevent unauthorized script execution.
  • Regular Security Audits: Continuously assess system vulnerabilities and apply necessary patches.

Skitnet represents a significant threat to cybersecurity, offering ransomware gangs a powerful post-exploitation tool. As its adoption grows, organizations must stay vigilant, proactive, and adaptive in their security strategies to mitigate its impact.

At 2W Tech, we are dedicated to helping businesses combat ransomware attacks through our comprehensive cybersecurity solutions. With our reliable expertise, we implement robust security measures, including advanced threat detection and prevention, regular system updates, and employee training programs to recognize and mitigate risks. Our managed IT services ensure continuous monitoring and quick response to potential threats, safeguarding your data and operations. By prioritizing effortless technology and sensible innovation, we provide tailored strategies that not only protect against ransomware but also empower your organization to thrive in a secure digital environment. With 2W Tech as your ally, you can confidently focus on your business while we manage the complexities of cybersecurity.

Read More:

Optimizing Hybrid Work with Microsoft Teams

Epicor Prophet 21 is The Leading ERP for Distributors

Back to IT News

Copyright © 2025, 2W Technologies, Inc.

2W Tech is a leading technology service provider specializing in cutting-edge solutions for the manufacturing and distribution industry, including Epicor ERP, Epicor P21, IT support and infrastructure, Azure cloud services, Microsoft 365, cybersecurity, artificial intelligence, data analytics, and comprehensive managed technology programs.

Epicor in AzureTM and ResolveIQTM are registered trademarks of 2W Technologies, INC.

As an esteemed Epicor Platinum Elite Partner and a Microsoft Tier 1 Cloud Services Partner, we are dedicated to delivering unparalleled service and support. For more information, please contact us at 262-686-5070 or visit our website here.