PS1
MITRE ATT&CK: S0613 View on attack.mitre.org
Aliases: PS1
- Malware type
- loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 4 (3 malicious)
- Last IoC activity
- 2026-08-21 18:54:30
- Profile updated
- 2026-07-07 13:10:12
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:cr
Context
PS1 is a loader that was used to deploy 64-bit backdoors in the CostaRicto campaign.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to PS1 (S0613). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 212.56.35.232 | 2026-08-21 | 3 |
| URL | http://193.112.251.31:8888/PowerView.ps1 | 2026-01-14 | 1 |
| URL | https://212.56.35.232/ | 2025-08-14 | 1 |
Detection coverage
- 269 Sigma rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- PowerShell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- CostaRicto (campaign)
Reports & references
- blogs.blackberry.com — The Costaricto Campaign Cyber Espionage Outsourced (report)
- MITRE ATT&CK — S0613 (report)