PS1 is custom malware associated with the CostaRicto threat activity. The provided content identifies PS1 as one of several bespoke malware families used by CostaRicto, alongside CostaBricks and SombRAT. Reported capabilities include use of a PowerShell loader and the ability to inject its payload DLL into memory, indicating in-memory execution and likely defense-evasion tradecraft. No additional high-confidence details on infection vector, platform scope, targeting, or indicators of compromise are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enterprise New Software: ... PS1
Malware that can utilize a PowerShell loader.
Custom malware used by CostaRicto.
Custom malware used by CostaRicto.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.