PS1Bot is a modular multi-stage malware framework and information stealer implemented in PowerShell and C#. Cisco Talos observed it in active campaigns throughout 2025, and Red Canary tracked it from March 2025 with increased activity into early 2026. Initial access is commonly associated with malvertising and SEO-poisoning lures that deliver malicious ZIP archives, often named to match user search terms. These archives contain a JavaScript downloader such as "FULL DOCUMENT.js" executed via wscript.exe; the downloader retrieves additional script content from attacker-controlled infrastructure, writes a PowerShell script to disk under locations such as C:\ProgramData, and begins command-and-control polling. Talos reported that PS1Bot constructs parts of its C2 URL path using the serial number of the C:\ drive and executes returned PowerShell content via Invoke-Expression, while follow-on modules are often executed in memory to minimize disk artifacts and forensic visibility.
Observed PS1Bot capabilities include antivirus discovery via WMI, system and environment reconnaissance, screenshot capture, keylogging, clipboard capture, information theft, and persistence. The screenshot module dynamically compiles C# at runtime using PowerShell Add-Type, captures the screen, converts and Base64-encodes the image, uploads it to C2, and deletes temporary image files. The keylogging and clipboard module dynamically compiles and executes a C# DLL and uses Windows API functionality including SetWindowsHookEx() to capture keyboard and mouse events and monitor clipboard contents. An information collection module named "WMIComputerCSHARP" gathers host and domain-related information using WMI and the %USERDNSDOMAIN% environment variable.
The grabber and stealer functionality targets browser credentials, cookies, cryptocurrency wallet data, MFA-related data, local wallet application data, passwords, and wallet seed phrases. Reported browser targets include Chrome, Edge, Brave, Opera, Vivaldi, Yandex, and other Chromium-based browsers. Reported extension and application targets include MetaMask, Ledger, Trust Wallet, Coinbase, Phantom, Ronin, Exodus, Yoroi, Authenticator, Authy Desktop, Atomic, Armory, Electrum, Coinomi, Daedalus, Bitcoin Core, Ledger Live, Guarda, Binance, Zcash, and TrustWallet. Talos reported that the stealer uses embedded wordlists, including multilingual variants such as Czech, to scan local drives for files of selected extensions and sizes containing sensitive strings, passwords, or wallet seed phrases. Collected data is compressed and exfiltrated via HTTP POST, while some data such as antivirus results and detected seed phrases may be sent via HTTP GET.
Persistence has been observed through creation of a randomly named directory under %PROGRAMDATA%, storage of a PowerShell script and ICO file there, and placement of a malicious LNK file in the Startup directory. Red Canary also observed PS1Bot installations placing files in randomly named ProgramData subdirectories with randomly named PowerShell scripts. Reported overlaps include code and infrastructure similarities with Skitnet/Bossnet activity and architectural similarities with AHK Bot, including modular task delivery and drive-serial-based C2 URL construction. Talos linked the broader activity cluster to prior ransomware-related campaigns involving Skitnet/Bossnet, and Red Canary observed PS1Bot activity preceding execution of the Rhadamanthys information stealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
This PowerShell module... is responsible for obtaining and reporting the antivirus programs present on the infected system. This is accomplished by querying Windows Management Instrumentation (WMI)...
Cisco Talos has observed an ongoing malware campaign that seeks to infect victims with a multi-stage malware framework, implemented in PowerShell and C#...
This includes writing a PowerShell script to C:\ProgramData\ ... Any PowerShell content received is then passed to Invoke-Expression (IEX) and executed within the existing PowerShell process.
the JS file contained VBScript... | In the cases analyzed, the JS file contained VBScript, which employed a variety of obfuscation methods throughout 2025.
When executed, the malware retrieves a JScript scriptlet from an attacker controlled server, the contents of which are then executed. | Inside of the compressed archive is a single file called “FULL DOCUMENT.js” that functions as a downloader... the JS file contained VBScript...
This is often performed for a variety of reasons, including to identify when systems may be in active use by victims versus unattended...
the %USERDNSDOMAIN% environment variable is also queried to attempt to enumerate the domain membership of the infected system.
This PowerShell script obtains the serial number of the C:\ drive and uses it to construct a URL...
It is designed to target the following types of data that are then exfiltrated to the C2 server: Local browser storage... Local application data for cryptocurrency wallet applications... Files containing passwords...
The keylogger uses SetWindowsHookEx() to monitor keyboard and mouse events to facilitate the capture of keystrokes and mouse activity on the system.
we have observed the delivery of additional PowerShell modules, one of which is used to capture screenshots on infected systems and transmit the resulting images to the C2 server.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Modular PowerShell/.NET-based infostealer with keylogging, screen capture, and file/credential collection capabilities; commonly installed via SEO poisoning/malvertising leading to a malicious ZIP containing a JavaScript dropper executed by wscript.exe, which downloads and installs PS1Bot under ProgramData and runs additional .NET-bearing PowerShell scriptloads.
Modular multi-stage in-memory malware framework delivered via malvertising; supports info theft, keylogging, recon, and persistence (per summary).
A modular malware framework that controls PowerShell payload execution through modules delivered from an external server.
Multi-stage, modular PowerShell/C# malware delivered via malvertising/SEO poisoning. Uses in-memory execution to reduce disk artifacts, contacts C2 to fetch additional PowerShell modules, and supports capabilities including reconnaissance, information theft (including crypto wallet/seed phrase hunting), keylogging/clipboard capture, screenshot capture, AV discovery, and persistence via auto-start on reboot.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.