TF-MAL-ps1.powershell_web_backdoor
📛 Threat Title
Malware family: powershell_web_backdoor
Description
ThreatFox malware family `ps1.powershell_web_backdoor`. Printable name: powershell_web_backdoor.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arstechnica.com
Suspected China-state hackers used update infrastructure to deliver backdoored version.
-
web:cybersecuritynews.com
A sophisticated PowerShell-based malware named TAMECAT has emerged as a critical threat to enterprise security, targeting login credentials stored in Microsoft Edge and Chrome browsers.
-
web:github.com
Guidance for mitigation web shells. #nsacyber. Contribute to nsacyber/Mitigating-Web-Shells development by creating an account on GitHub.
-
web:hoploninfosec.com
TAMECAT PowerShell backdoor detection and removal explained. Learn how Edge and Chrome credentials may be exposed, what's confirmed, and how to stay protected.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the powershell_web_backdoor malware family including references, samples and yara signatures.
-
web:malwaretips.com
A sophisticated PowerShell-based malware named TAMECAT has emerged as a critical threat to enterprise security, targeting login credentials stored in Microsoft Edge and Chrome browsers. This malware operates as part of espionage campaigns conducted by APT42, an Iranian state-sponsored...
-
web:medium.com
When APTs Iterate: A Deep Dive into COLDRIVER's ROBOT Malware Chain A technical analysis of MAYBEROBOT, the PowerShell backdoor deployed by Russian FSB after their tools were exposed
-
web:www.cisa.gov
After gaining initial access, the malicious cyber actor deployed malware that scanned the environment for sensitive credentials. The cyber actor then targeted GitHub Personal Access Tokens (PATs) and application programming interface (API) keys for cloud services, including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft ...
-
web:www.microsoft.com
Signed malware backed by a stolen EV certificate deployed legitimate RMM tools to gain persistent access inside enterprise environments. Organizations must harden certificate controls and monitor RMM activity to reduce exposure.
-
web:www.sophos.com
What to do Customers running on-premises SharePoint instances are advised to apply the official patches from Microsoft and follow the supplied recommendations for mitigation . Users unable to patch for whatever reason should consider taking instances offline temporarily.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.