Researchers reported that PsiXBot, a modular .NET malware family first seen in 2017, matured into a more capable bot focused on credential theft, surveillance, and remote control. The malware was observed spreading through malspam, SmokeLoader, and the Spelevo Exploit Kit, then installing under %APPDATA%, avoiding systems configured for the Russian language, and using RC4-encrypted communications. Its feature set grew to include browser and Outlook credential theft, keylogging, form grabbing, clipboard cryptocurrency hijacking, remote desktop access, persistence, and download-and-execute functions delivered through separate modules.
Later analysis showed PsiXBot updating its command-and-control discovery to better support resilient Namecoin .bit domains, including the use of tiny[.]cc shortened links and hex-encoded values to retrieve DNS server IP addresses for resolving its infrastructure. The bot continued to collect host data, check in over encrypted HTTPS, and receive commands for tasks such as spam sending through Microsoft Outlook, scheduled execution, and additional foreground modules. The use of .bit domains aligns with broader concerns that decentralized naming systems can provide a form of bulletproof hosting that complicates takedowns and infrastructure disruption.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Fox-IT observed the Spelevo exploit kit distributing PsiXBot, documenting exploit-kit-based delivery of the malware.
Fox-IT observed SmokeLoader delivering a PsiXBot sample, showing the malware was being spread through loader-based distribution in addition to other vectors.
Fox-IT reported that by early 2019 PsiXBot had matured into a more capable modular bot with expanded core functionality and modules for credential theft, keylogging, remote access, persistence, and download-and-execute tasks.
Fox-IT noted an updated PsiXBot sample observed in August 2018, indicating ongoing development of the malware family before its later modular expansion.
Fox-IT reported that the modular .NET malware family PsiXBot was first observed in the wild in mid-2017.
Proofpoint identified newly implemented StartFGModule and StartSpam capabilities in PsiXBot 1.0.2, expanding the malware with form grabbing and outbound spam-sending through Microsoft Outlook.
Proofpoint reported that PsiXBot version 1.0.2 changed its command-and-control discovery method by using tiny[.]cc shortened URLs and hex-encoded values to retrieve DNS server IPs for resolving NameCoin .bit domains.
Proofpoint researchers observed a new PsiXBot version, 1.0.2, continuing to spread via malicious spam and exploit kit campaigns including Spleevo and RIG-v.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 74 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
5 references tracked. Mallory keeps watching after this page renders.
proofpoint.com
Open sourceproofpoint.com
Open sourceblog.fox-it.com
Open sourceabuse.ch
Open sourcetools.ietf.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.