s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.unidentified_002

📛 Threat Title

Malware family: Unidentified PS 002 (RAT)

Category: Unidentified PS 002 (RAT) First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.unidentified_002`. Printable name: Unidentified PS 002 (RAT).

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:attack.mitre.org

    MITRE ATT&CK ® is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. The ATT&CK knowledge base is used as a foundation for the development of specific threat models and methodologies in the private sector, in government, and in the cybersecurity product and service community. With the creation of ATT&CK, MITRE is fulfilling its mission ...

  • web:cybersecsentinel.com

    Atroposia is a commercially available Remote Access Trojan delivered through a Malware as a Service model. It is engineered for evasion and modularity. The platform provides operators with a builder that outputs native, dependency free stubs for Windows that are unique per build. This approach defeats signature based detection.

  • web:gbhackers.com

    A new wave of cyber threats has emerged with the discovery of updated variants of Chaos RAT , a notorious open-source remote administration tool (RAT) first identified in 2022. As reported by Acronis TRU researchers in their recent 2025 analysis, this malware continues to evolve, targeting both Linux and Windows environments with sophisticated capabilities for espionage and data exfiltration ...

  • web:github.com

    Campaign Identifiers: New profile names, session IDs, or reckey values decoded from JWrapper logs. Behavioral Signatures: New TTPs, security product polling behavior, or RMM agent uninstall scripts observed in the wild. Remediation Improvements: Updates to Check-System.ps1, Fix.ps1, or RUN_ME.bat to handle new malware variants or edge cases.

  • web:hivepro.com

    The malware's low detection rates and open-source nature make it attractive for espionage, data exfiltration, and establishing persistent footholds for ransomware and other post-compromise operations. Its availability on GitHub allows threat actors to modify and repurpose it, complicating attribution and defense efforts. Chaos RAT exemplifies how legitimate open-source tools can be ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Unidentified PS 002 (RAT) Propose Change A Powershell-based RAT capable of pulling further payloads, delivered through Russia-themed phishing mails.

  • web:steamcommunity.com

    Sort by: Results for "incident wife hana walkthrough" Showing 1-6 of 6 entries In forum " Pathfinder: Kingmaker General Discussions " 137 Thinking of buying Aug 25, 2019 @ 9:26am Cutlass Jack [/quote]

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.infosecurity-magazine.com

    A newly uncovered remote access Trojan (RAT) that operated for weeks on a compromised system has been discovered and analyzed by security researchers. According to Fortinet's FortiGuard Incident Response Team, the malware , which ran within a legitimate Windows process, used advanced evasion techniques to make recovery and inspection more difficult. In-Memory Only Malware with Corrupted ...

  • web:www.malwarebytes.com

    Get everything you need to know about Remote Access Trojans (RAT) from what are they, the history of RAT , common infection methods, how to remove them & much more.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.