TF-MAL-ps1.wrecksteel
📛 Threat Title
Malware family: WRECKSTEEL
Description
ThreatFox malware family `ps1.wrecksteel`. Printable name: WRECKSTEEL.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ps1.wrecksteel
IOC database
- Type
- domain
- Value
ps1.wrecksteel- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ps1.wrecksteel
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:blog.netmanageit.com
The primary tool, classified as WRECKSTEEL , exists in both VBScript and PowerShell versions. Earlier attacks in 2024 used EXE files created with NSIS installers, containing decoy documents and the IrfanView program for screenshots.
-
web:cyberpress.org
According to the Report, The WRECKSTEEL malware exists in multiple versions written in VBScript and PowerShell, underscoring its adaptability. The use of compromised accounts to distribute phishing emails further complicates attribution and mitigation efforts. CERT-UA urges all organizations to remain vigilant against this threat.
-
web:cybersecuritynews.com
Ukrainian government agencies and critical infrastructure are facing targeted cyberattacks from threat actor UAC-0219 using the information stealer WRECKSTEEL . The campaign distributes phishing emails with malicious links to public file services like DropMeFiles and Google Drive, often embedded in official-looking PDF attachments with names ...
-
web:gbhackers.com
WRECKSTEEL : A Versatile Data-Stealing Tool The WRECKSTEEL malware is central to these operations and exists in both VBScript and PowerShell variants. Its primary function is to systematically steal files from compromised systems.
-
web:malpedia.caad.fkie.fraunhofer.de
WRECKSTEEL Propose Change According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be then uploaded via cURL.
-
web:securityaffairs.com
CERT-UA reports attacks in March 2025 targeting Ukrainian agencies with WRECKSTEEL Malware CERT-UA reported three cyberattacks targeting Ukraine's state agencies and critical infrastructure to steal sensitive data. The Computer Emergency Response Team of Ukraine (CERT-UA) reported three cyberattacks in March 2025 targeting Ukrainian agencies and infrastructure to steal sensitive data. This ...
-
web:socprime.com
In March 2025, at least three cyber-attacks against government agencies and the critical infrastructure sector in Ukraine were observed in the cyber threat landscape linked to the UAC-0219 hacking group. Adversaries primarily relied on WRECKSTEEL malware designed for file exfiltration, available in both its VBScript and PowerShell iterations.
-
web:techinvestornews.io
Apr 04, 2025 Ravie LakshmananCritical Infrastructure / Malware The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed that no less than three cyber attacks were recorded against state administration bodies and critical infrastructure facilities in the country with an aim to steal sensitive data.
-
web:undercodenews.com
A Growing Cyber Threat in Ukraine Ukraine's Computer Emergency Response Team (CERT-UA) has issued an alarming report on a series of cyberattacks carried out by the hacking group UAC-0219. Since late 2024, these attackers have used a sophisticated PowerShell-based malware known as " WRECKSTEEL " to steal sensitive data from government agencies and critical infrastructure. This ongoing cyber ...
-
web:www.fortinet.com
FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.