Octopus (Powershell)

Malware type
rat
Family
Malware family
Profile updated
2026-07-07 14:38:44

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

The author describes Octopus as an "open source, pre-operation C2 server based on python which can control an Octopus powershell agent through HTTP/S." It is different from the malware win.octopus written in Delphi and attributed to DustSquad by Kaspersky Labs.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Ps1.Octopus (report)
  • resources.malwarebytes.com — Lazyscripter (report)
  • isc.sans.edu — 26918 (report)
  • go.recordedfuture.com — Cta 2021 0107 (report)
  • github.com — Octopus (report)
  • isc.sans.edu — 28628 (report)

External references