216.73.217.55

Malvertising campaign leads to PS1Bot, a multi-stage malware framework

· Published 12/08/2025 21:36 · Modified 13/08/2025 10:50

Export JSON

Essential information

Published
12/08/2025 21:36
Modified
13/08/2025 10:50
Tags
2025-08-12 ahk bot c++ cryptocurrency in-memory execution information stealer malvertising modular multi-stage powershell ps1bot skitnet
Related entities
18 techniques (mitre), 3 malware

Description

A malware campaign utilizing has been distributing , a sophisticated framework implemented in and C#. features design, enabling information theft, keylogging, reconnaissance, and persistent system access. The malware minimizes artifacts and uses techniques for stealth. Active since early 2025, 's targets wallets and employs wordlists to identify files containing passwords and seed phrases. The campaign overlaps with previously reported activities and uses similar C2 infrastructure. Delivery involves compressed archives with obfuscated scripts, leading to modules for antivirus detection, screen capture, data theft, keylogging, and system information collection. Persistence is established through startup directory manipulation.

External references