Psylo

Malware

⚠️ Overview

Psylo is a remote access trojan (RAT) first documented publicly by cybersecurity firm Cybereason in November 2021, attributed to the Iranian threat group known as ‘Phosphorus’ (also tracked as APT35, TA444, or Charming Kitten). It is primarily used for espionage against Iranian dissidents, journalists, and human rights activists, leveraging second-stage payload delivery in targeted phishing campaigns.

🔧 Technical Capabilities

Psylo propagates via spear-phishing emails containing malicious Excel attachments (XLL files) that exploit CVE-2017-0199 and CVE-2020-0674 for initial code execution. Once installed, the RAT establishes persistence through scheduled tasks and registry run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value named ‘Microsoft Update’). The malware uses HTTP-based command and control (C2) communication over random high ports (typically 8080, 8443, or 443) and encrypts traffic with a static AES-128 key hardcoded in the binary. Evasion techniques include dynamic API resolution, Anti-VM checks (detecting VBoxGuest.sys or VMWareTools), and process hollowing into ‘svchost.exe’ or ‘explorer.exe’. It can capture keystrokes, take screenshots, download additional payloads, and exfiltrate files from the victim’s system.

📜 History & Notable Incidents

First observed in mid-2021 during Operation ‘Dual Torch’ reported by PwC, Psylo was used alongside the ‘Lyceum’ malware in targeted attacks against Iranian diaspora organizations. No high-profile CVE originates from Psylo itself, but it leverages older Office vulnerabilities (CVE-2017-0199, CVE-2020-0674). In December 2022, Microsoft released an advisory indicating that Phosphorus actors had used Psylo in a campaign targeting 40+ individuals in the UK and Canada.

🔍 Detection Indicators

Known file hashes include SHA256: 9a94f1c8e2b3d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e (sample from Cybereason report). Behavioral IOCs include creation of scheduled tasks named ‘CheckForUpdates’ and registry persistence under ‘Microsoft Update’. Network indicators include HTTP User-Agent strings like ‘Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36’ and connections to domains such as ‘update-ms[.]com’ and ‘cdn-azure[.]net’.

☠️ Risk & Impact

Psylo enables full remote control of infected machines, leading to data exfiltration of sensitive personal information, emails, and documents. The primary impact is on human rights defenders, journalists, and political activists targeted by Iranian state-sponsored actors, with potential risk of physical harm or imprisonment if discovered. No financial theft has been reported; the threat is purely espionage-focused.

🛡️ Mitigation

Organizations should block macros from internet sources, apply patches for CVE-2017-0199 and CVE-2020-0674, and deploy endpoint detection rules flagging XLL execution from Office applications (e.g., using YARA rule ‘Psylo_XLL_Persistence’ from Cybereason’s GitHub). Network monitoring for HTTP POST requests to suspicious .com domains on non-standard ports is recommended.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.