PS1Bot

Malware type
botnet, credential-stealer, keylogger, screen-capture
Family
Malware family
Profile updated
2026-07-07 14:38:14

Context

According to Cisco Talos, this is multi-stage malware framework, implemented in PowerShell and C#, that possesses robust functionality, including the ability to deliver follow-on modules including an information stealer, keylogger, screen capture collector and more. It also establishes persistence to continue operations following system reboots. The design of this malware framework appears to attempt to minimize artifacts left on infected systems by facilitating the delivery and execution of modules in-memory, without requiring them to be written to disk. Due to similarities in the design and implementation with the malware family AHK Bot, we are referring to this PowerShell-based malware as “PS1Bot.”

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Php.Ps1Bot (report)
  • Cisco Talos — Ps1Bot Malvertising Campaign (report)

External references