TF-MAL-ps1.choco_shell
📛 Threat Title
Malware family: ChocoShell
Description
ThreatFox malware family `ps1.choco_shell`. Printable name: ChocoShell.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cyfar.ca
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Microsoft Threat Intelligence identifies Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread captive portal traffic manipulation attacks since May 2026 targeting travelers at hospitality venues worldwide. The campaign delivers CornFlake, a Go-based Windows RAT with ...
-
web:hunt.io
Discover detailed profiles of malware families, including threat actor data, mitigation strategies, and targeted industries to enhance your defenses.
-
web:learn.microsoft.com
Find Microsoft's detection name for a malware family in Defender for Endpoint. Learn how Microsoft malware naming works and how to look up the corresponding detection name.
-
web:malpedia.caad.fkie.fraunhofer.de
ChocoShell Propose Change Actor (s): APT29 According to Microsoft Threat Intelligence, ChocoShell is a PowerShell-based information stealer delivered and executed entirely in memory, with the primary objective of harvesting browser session cookies, saved passwords, Microsoft 365 SSO tokens, and Wi-Fi credentials from compromised systems.
-
web:malpedia.caad.fkie.fraunhofer.de
This page gives an overview of all malware families that are covered on Malpedia, supplemented with some basic information for each family .
-
web:marcusbotacin.github.io
Malware classification is a critical task in computer security since it allows the identification and mitigation of potential cybersecurity threats. Convolutional Neural Networks (CNN) have proven to be an efective tool in malware detection, especially when combined with the transfer learning technique.
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.microsoft.com
Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands. This campaign evades traditional defenses by stealing credentials, wallets, and sensitive data.
-
web:www.microsoft.com
ACR Stealer is an information-stealing malware family reportedly offered through a malware -as-a-service (MaaS) model and associated with the rebranding of Amatera Stealer. During this period, two campaigns stand out, together appearing frequently in reviewed recent intrusions.
-
web:www.ncsc.gov.uk
This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.