Skitnet, also referred to as Bossnet, is malware used in ransomware-related post-exploitation activity to steal sensitive data and establish remote control over compromised hosts. Reporting cited in the provided content states that several ransomware actors have used Skitnet for data theft and remote access objectives. WardenShield described Skitnet/Bossnet as a new malware loader sold under a malware-as-a-service model on underground forums since April 2024. Cisco Talos reported overlap between a 2025 PS1Bot campaign and previously reported Skitnet/Bossnet activity, including matching PowerShell-based components, code and command-and-control infrastructure overlap, and similar architectural patterns. Talos noted it did not directly observe delivery of a Skitnet binary in the infection chains it analyzed, but assessed that the PowerShell implementation described in prior Skitnet reporting matched components delivered in that campaign. High-confidence capabilities directly mentioned for Skitnet in the content are data theft and establishing remote control over infected systems; no specific indicators of compromise are provided in the source material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-exploitation malware used for stealthy data theft and remote control; sold on underground forums (RAMP) since April 2024.
Post-exploitation malware used by ransomware operators for stealthy data theft and remote access/control on compromised networks.
Malware used in ransomware-related campaigns to steal data and provide remote control over compromised hosts.
Skitnet, also referred to as Bossnet in the content, is referenced as related prior malware reporting with overlapping PowerShell components and C2 infrastructure, but Talos did not observe direct delivery of the Skitnet binary in the analyzed infection chains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.