TookPS is a Windows PowerShell-based downloader used as the initial stage of a broader multi-stage intrusion chain associated with the OkoBot campaign. Active since at least March 2025, it has been delivered through social-engineering lures including ClickFix-style prompts and trojanized software distributed via fraudulent GitHub repositories impersonating legitimate tools. TookPS has also been observed in fake software and fake AI-client distribution campaigns.
After execution, TookPS retrieves and runs additional commands and scripts from attacker-controlled infrastructure. A defining behavior is installation and configuration of SSH to establish a tunnel from the victim host to attacker infrastructure, enabling remote access and follow-on automation. Subsequent operator or bot activity through that tunnel has included host inventory, theft of cryptocurrency wallet files, browser profiles, cookies, and credentials, delivery of additional malware modules over SSH/SFTP, and establishment of persistent access. In OkoBot-related intrusions, the broader post-compromise chain enabled remote desktop access, suppression of security notifications, scheduled-task persistence, browser extension abuse, keylogging, targeted surveillance of wallet and password-manager applications, and theft of cryptocurrency recovery phrases through later-stage modules.
TookPS is best characterized as an initial-access and staging component rather than the full capability set of the downstream framework it helps deploy. It has been linked to campaigns with global victimology and especially high impact in Brazil, Vietnam, Canada, Mexico, and Türkiye. Public reporting has not conclusively attributed the activity to a known threat group, though some tradecraft and language artifacts have been assessed as consistent with a suspected Russian-speaking operator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Using fraudulent GitHub repositories to distribute malicious batch script installers masquerading as legitimate IT and security software, leading to the deployment of the TookPS downloader, which then initiates a multi-stage infection chain to establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT).
Using fraudulent GitHub repositories to distribute malicious batch script installers masquerading as legitimate IT and security software, leading to the deployment of the TookPS downloader, which then initiates a multi-stage infection chain to establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT).
Using fraudulent GitHub repositories to distribute malicious batch script installers masquerading as legitimate IT and security software, leading to the deployment of the TookPS downloader, which then initiates a multi-stage infection chain to establish persistent remote access using SSH reverse tunnels and RATs like MineBridge RAT (aka TeviRAT).
20 distinct techniques documented for this family, organized by ATT&CK tactic.
If the warning returns at a regular interval, Task Scheduler is the first place to correlate.
ClickFix attacks display fake errors or verification instructions that persuade users to copy and run commands in PowerShell or the Windows Run dialog.
When Defender displays C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe , it may be reporting a suspicious command observed through Antimalware Scan Interface rather than a malicious copy of PowerShell.
This command starts an SSH server, thereby establishing a tunnel between the infected device and the remote server.
43 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A PowerShell downloader/loader in the OkoBot infection chain that installs SSH, establishes the tunnel to attacker infrastructure, and supports payload delivery and exfiltration.
PowerShell-компонент, используемый в цепочке заражения OkoBot для установки SSH, создания туннеля к инфраструктуре злоумышленников и подготовки доступа для последующих автоматизированных действий.
PowerShell downloader used after initial infection to establish SSH connectivity to attacker infrastructure and facilitate exfiltration of sensitive data.
A malicious PowerShell script used in the campaign to establish initial remote connectivity by installing SSH, connecting to attacker infrastructure, and enabling collection of host and user data for follow-on compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.