TF-MAL-ps1.unidentified_003
📛 Threat Title
Malware family: Unidentified PS 003 (RAT)
Description
ThreatFox malware family `ps1.unidentified_003`. Printable name: Unidentified PS 003 (RAT).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix ...
-
web:gbhackers.com
A new wave of cyber threats has emerged with the discovery of updated variants of Chaos RAT , a notorious open-source remote administration tool (RAT) first identified in 2022. As reported by Acronis TRU researchers in their recent 2025 analysis, this malware continues to evolve, targeting both Linux and Windows environments with sophisticated capabilities for espionage and data exfiltration ...
-
web:github.com
Campaign Identifiers: New profile names, session IDs, or reckey values decoded from JWrapper logs. Behavioral Signatures: New TTPs, security product polling behavior, or RMM agent uninstall scripts observed in the wild. Remediation Improvements: Updates to Check-System.ps1, Fix.ps1, or RUN_ME.bat to handle new malware variants or edge cases.
-
web:hivepro.com
The malware's low detection rates and open-source nature make it attractive for espionage, data exfiltration, and establishing persistent footholds for ransomware and other post-compromise operations. Its availability on GitHub allows threat actors to modify and repurpose it, complicating attribution and defense efforts. Chaos RAT exemplifies how legitimate open-source tools can be ...
-
web:hunt.io
Chaos RAT is a Go-based remote access trojan (RAT) that targets Windows and Linux, enabling attackers to execute commands, steal data, and mine Monero (XMR) on compromised systems.
-
web:malpedia.caad.fkie.fraunhofer.de
Unidentified PS 003 (RAT) Propose Change This malware is a RAT written in PowerShell. It has the following capabilities: Downloading and Uploading files, loading and execution of a PowerShell script, execution of a specific command.
-
web:snyk.io
Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here's what happened, who's affected, and how to check your exposure.
-
web:www.anyviewer.com
This post primarily introduces how to detect Remote Access Trojan and how to get rid of Remote Access Trojan on computer. It offers various tips and strategies for addressing this security threat.
-
web:www.infosecurity-magazine.com
A newly uncovered remote access Trojan (RAT) that operated for weeks on a compromised system has been discovered and analyzed by security researchers. According to Fortinet's FortiGuard Incident Response Team, the malware , which ran within a legitimate Windows process, used advanced evasion techniques to make recovery and inspection more difficult. In-Memory Only Malware with Corrupted ...
-
web:www.pcrisk.com
What is Chaos RAT ? STEP 1. Manual removal of Chaos RAT malware . STEP 2. Check if your computer is clean. How to remove malware manually? Manual malware removal is a complicated task - usually it is best to allow antivirus or anti- malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.