TF-MAL-ps1.unidentified_004
📛 Threat Title
Malware family: Unidentified PS 004 (RAT)
Description
ThreatFox malware family `ps1.unidentified_004`. Printable name: Unidentified PS 004 (RAT).
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
COATHANGER is a remote access tool (RAT) targeting FortiGate networking appliances. First used in 2023 in targeted intrusions against military and government entities in the Netherlands along with other victims, COATHANGER was disclosed in early 2024, with a high confidence assessment linking this malware to a state-sponsored entity in the ...
-
web:cybersecsentinel.com
Atroposia is a commercially available Remote Access Trojan delivered through a Malware as a Service model. It is engineered for evasion and modularity. The platform provides operators with a builder that outputs native, dependency free stubs for Windows that are unique per build. This approach defeats signature based detection.
-
web:cybersecuritytimes.com
A sophisticated multi-stage malware delivery campaign has been uncovered, combining Unicode-obfuscated VBS launchers, PNG-embedded payloads, and an in-memory .NET loader to deploy remote access trojans all operated through an openly accessible attacker-controlled directory infrastructure. The investigation originated within LevelBlue's MDR SOC after SentinelOne flagged a suspicious Visual ...
-
web:cybersight-security.github.io
Home Remote Access Trojans Remote Access Trojans These sophisticated malware variants are designed to infiltrate systems, granting cybercriminals remote control and access. They often operate covertly, evading detection while enabling a range of malicious activities such as data theft, surveillance, or even system manipulation. RATs are notorious for exploiting vulnerabilities in security ...
-
web:gbhackers.com
A new wave of cyber threats has emerged with the discovery of updated variants of Chaos RAT , a notorious open-source remote administration tool (RAT) first identified in 2022. As reported by Acronis TRU researchers in their recent 2025 analysis, this malware continues to evolve, targeting both Linux and Windows environments with sophisticated capabilities for espionage and data exfiltration ...
-
web:github.com
Campaign Identifiers: New profile names, session IDs, or reckey values decoded from JWrapper logs. Behavioral Signatures: New TTPs, security product polling behavior, or RMM agent uninstall scripts observed in the wild. Remediation Improvements: Updates to Check-System.ps1, Fix.ps1, or RUN_ME.bat to handle new malware variants or edge cases.
-
web:hivepro.com
The malware's low detection rates and open-source nature make it attractive for espionage, data exfiltration, and establishing persistent footholds for ransomware and other post-compromise operations. Its availability on GitHub allows threat actors to modify and repurpose it, complicating attribution and defense efforts. Chaos RAT exemplifies how legitimate open-source tools can be ...
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Unidentified PS 004 (RAT) malware family including references, samples and yara signatures.
-
web:www.acronis.com
Acronis TRU identified new variants of Chaos RAT , a known malware family , in recent real-world Linux and Windows attacks. Chaos RAT is an open-source remote administration tool (RAT) first seen in 2022. It evolved in 2024, and new samples have been discovered by TRU in 2025. TRU researchers uncovered a critical vulnerability in Chaos RAT's web panel that allows attackers to execute remote ...
-
web:www.morphisec.com
The malware uses the resource resolution handler to detect certain analysis environments: By monitoring which assemblies are requested and when, the malware can identify patterns typical of dynamic analysis tools and adjust its behavior accordingly.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.