s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.wrecksteel

📛 Threat Title

Malware family: WRECKSTEEL

Category: WRECKSTEEL First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.wrecksteel`. Printable name: WRECKSTEEL.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.wrecksteel

IOC database

Type
domain
Value
ps1.wrecksteel
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.wrecksteel

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    The primary tool, classified as WRECKSTEEL , exists in both VBScript and PowerShell versions. Earlier attacks in 2024 used EXE files created with NSIS installers, containing decoy documents and the IrfanView program for screenshots.

  • web:cyberpress.org

    According to the Report, The WRECKSTEEL malware exists in multiple versions written in VBScript and PowerShell, underscoring its adaptability. The use of compromised accounts to distribute phishing emails further complicates attribution and mitigation efforts. CERT-UA urges all organizations to remain vigilant against this threat.

  • web:cybersecuritynews.com

    Ukrainian government agencies and critical infrastructure are facing targeted cyberattacks from threat actor UAC-0219 using the information stealer WRECKSTEEL . The campaign distributes phishing emails with malicious links to public file services like DropMeFiles and Google Drive, often embedded in official-looking PDF attachments with names ...

  • web:gbhackers.com

    WRECKSTEEL : A Versatile Data-Stealing Tool The WRECKSTEEL malware is central to these operations and exists in both VBScript and PowerShell variants. Its primary function is to systematically steal files from compromised systems.

  • web:malpedia.caad.fkie.fraunhofer.de

    WRECKSTEEL Propose Change According to CERT-UA, this is a stealer targeting a range of file extensions and creating screenshots of the compromised machine to be then uploaded via cURL.

  • web:securityaffairs.com

    CERT-UA reports attacks in March 2025 targeting Ukrainian agencies with WRECKSTEEL Malware CERT-UA reported three cyberattacks targeting Ukraine's state agencies and critical infrastructure to steal sensitive data. The Computer Emergency Response Team of Ukraine (CERT-UA) reported three cyberattacks in March 2025 targeting Ukrainian agencies and infrastructure to steal sensitive data. This ...

  • web:socprime.com

    In March 2025, at least three cyber-attacks against government agencies and the critical infrastructure sector in Ukraine were observed in the cyber threat landscape linked to the UAC-0219 hacking group. Adversaries primarily relied on WRECKSTEEL malware designed for file exfiltration, available in both its VBScript and PowerShell iterations.

  • web:techinvestornews.io

    Apr 04, 2025 Ravie LakshmananCritical Infrastructure / Malware The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed that no less than three cyber attacks were recorded against state administration bodies and critical infrastructure facilities in the country with an aim to steal sensitive data.

  • web:undercodenews.com

    A Growing Cyber Threat in Ukraine Ukraine's Computer Emergency Response Team (CERT-UA) has issued an alarming report on a series of cyberattacks carried out by the hacking group UAC-0219. Since late 2024, these attackers have used a sophisticated PowerShell-based malware known as " WRECKSTEEL " to steal sensitive data from government agencies and critical infrastructure. This ongoing cyber ...

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.