PsiXBot is a modular .NET malware family first observed in 2017 and developed into a multi-function bot focused on credential theft, surveillance, spam propagation, and remote operator control. It has been distributed through malicious spam campaigns, exploit kits including Spelevo and RIG-v, and by other malware loaders such as SmokeLoader. Campaigns associated with PsiXBot have also appeared as downstream payloads in broader criminal delivery chains.
PsiXBot targets Windows systems and performs an anti-CIS check by exiting on systems configured for Russian language settings. It installs itself for continued execution and supports persistence through scheduled-task functionality. The malware collects host profiling data during check-in, including user, system, security-product, hardware, operating system, privilege, and domain-context information, then communicates with command-and-control infrastructure using RC4-encrypted POST traffic over HTTPS.
A defining characteristic of PsiXBot is its modular architecture. Observed core commands and modules support browser and Outlook credential theft, cookie theft, keylogging, form grabbing, process listing, software inventory, screenshot capture, download-and-execute, arbitrary command execution, self-deletion, and remote desktop-style interaction. Its browser theft component has been described as QuasarRAT-derived, and additional modules have included an Outlook spam component that sends attacker-crafted emails through the victim’s Microsoft Outlook account while reusing harvested signature data. Later versions also included a cryptocurrency clipboard hijacking module that replaces wallet addresses in the clipboard, and a so-called PornModule that monitors window titles for pornography-related terms and records audio and video, likely for extortion or blackmail.
PsiXBot’s command-and-control discovery and evasion mechanisms evolved over time. Earlier variants used hardcoded DNS infrastructure to resolve Namecoin .bit domains; later versions dynamically retrieved DNS resolver information via a URL-shortening service, and subsequent versions adopted Google DNS over HTTPS with fast-flux-backed infrastructure to conceal DNS lookups inside HTTPS traffic. Across versions, the malware remained under active development, with changes to check-in logic, infrastructure resolution, and module set indicating ongoing operator investment.
PsiXBot has been associated with financially motivated cybercrime activity and has appeared alongside other commodity malware families in shared criminal ecosystems. Its combination of credential theft, keylogging, form grabbing, Outlook-based spam propagation, remote access features, and extortion-oriented surveillance makes it a versatile Windows bot used for both direct monetization and follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We have observed final payloads including Ramnit, Gootkit, DarkVNC, Ursnif, and PsiXBot.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
On or around August 29, 2019, we observed a PsiXBot sample ... being dropped as a payload from Spelevo Exploit Kit.
We have continued to observe the malware in both malicious email and exploit kit campaigns. It has been historically delivered in both malicious spam campaigns...
The document itself contains malicious macros that will retrieve a payload of PsiXBot, and contains the above SpamModule configuration for further replication.
The emails are crafted in the targeted country’s language and are often personalized to include recipients’ names and addresses in various parts of the email such as email body and subject. TA554 frequently uses package delivery or order notification lures; the emails contain URLs linking to zipped LNK files or zipped documents.
The 'StartSpam' module... has the ability to send outbound email using Microsoft Outlook to send messages with varying content, crafted by the attacker... In addition to this, it will harvest any saved Outlook email signatures to be used inside any messages sent by this module.
In instances where it is not, it proceeds with the installation process, which is done by invoking the CopyEx method via WMI and invoking the copied binary again via WMI.
The current features contained in samples with version 1.0.3 are as follows... StartSchedulerModule
it was around this time that we also observed the samples resuming a practice from version 1.0.1, in which the C&C domains were hardcoded in the malware samples with RC4 encryption.
The C&C traffic continues to be POSTed and the client body data is still RC4-encrypted using a hardcoded key found in the sample.
The current features contained in samples with version 1.0.3 are as follows... SelfDelete
The 'SelfDelete' module runs a command using the cmd [.] exe shell in a hidden window to delete the running bot process and remove it from the infected system.
The current features contained in samples with version 1.0.3 are as follows... StartKeylogger
The 'StartFGModule'... is a newly implemented 'form grabbing' module... This module will store GET or POST requests in a log file titled 'temp.log' stored in the User’s %TEMP% directory. This log is subsequently sent to the C&C server.
"GetProcList" is new to these samples, but is functionally similar to the "GetProcessList" task observed in version 1.0.1.
The C&C check-in sequence remained largely the same, but was modified slightly to include a check for whether the infected machine is a member of a domain.
In addition to this, it will harvest any saved Outlook email signatures to be used inside any messages sent by this module.
The group also included anti-analysis and detection evasion features by implementing DNS over HTTPS and fast flux infrastructure.
The current features contained in samples with version 1.0.3 are as follows... StartKeylogger
The 'StartFGModule'... is a newly implemented 'form grabbing' module... This module will store GET or POST requests in a log file titled 'temp.log' stored in the User’s %TEMP% directory. This log is subsequently sent to the C&C server.
Once such an address is configured, the program proceeds to monitor the clipboard every 3 seconds and verifies if the copied text is a valid address... | If the check is successful the malware replaces the text with one of the configured wallet addresses;
...a new and unique method of dynamically fetching its own DNS infrastructure by utilizing a URL shortening service to gather the server IP addresses required to resolve the .bit domains used for command and control (C&C). | After this initial HTTP request to tiny[.]cc, the connection is upgraded to HTTPS... HTTPS traffic to the C&C domain... The data in the POST body is encrypted with RC4.
Proofpoint researchers observed the use of DNS over HTTPS to retrieve the IP address for the command and control (C&C) domains.
On or around August 29, 2019, we observed a PsiXBot sample ... being dropped as a payload from Spelevo Exploit Kit.
74 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet family observed in BraZZZers logs among multiple malware clients.
PsiXBot is a modular malware family under active development. In the described versions it uses hard-coded RC4-encrypted C2 domains, resolves them via Google DNS over HTTPS, communicates with C2 using RC4-encrypted POST data, and supports multiple modules for downloading and executing payloads, stealing cookies and passwords, collecting Outlook and software/process information, keylogging, crypto-related activity, spam propagation, and a blackmail/sexploitation module that records audio and video when pornography-related window titles are detected.
A modular .NET-based bot first emerged in 2017 and delivered via malicious email and exploit kits including Spleevo and RIG-v. It uses .bit/NameCoin-based C2 infrastructure, avoids infecting systems configured for Russian language, gathers host information, checks in to C2 over HTTPS with RC4-encrypted POST data, and retrieves commands to run modules. Capabilities described include downloading and executing payloads, stealing passwords and cookies, keylogging, form grabbing, clipboard cryptocurrency wallet replacement, Outlook-based spam sending, scheduler functionality, and self-deletion.
A modular .NET bot first seen in 2017 and actively distributed in early 2019 via exploit kits, malspam, and loaders. It installs itself for persistence, communicates with .bit C2 domains, profiles infected hosts, receives commands dynamically, and can download and execute modules for credential theft, keylogging, remote access, screenshotting, process listing, Outlook/browser theft, and cryptocurrency clipboard hijacking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.