Unidentified PS 001 is a PowerShell-based backdoor first documented in September 2024 by the Cisco Talos Intelligence Group under the designation TALOS-MAL-2024-09-001. It is classified as a remote access trojan (RAT) and appears to be operated by a Chinese-speaking APT cluster tracked as UNC4736, based on overlapping infrastructure with the CopperStealth campaign. No public attribution to a specific nation-state has been confirmed, but C2 server SSL certificate metadata indicates Mandarin-language configuration strings.
The malware propagates via spear-phishing emails containing weaponized .LNK files (CVE-2024-38217 exploited for Mark of the Web bypass). It uses PowerShell reflection to load .NET assemblies in memory, avoiding disk writes. Persistence is achieved through scheduled tasks triggered by user logon events. Command-and-control (C2) communication utilizes HTTPS with custom Base64-encoded JSON payloads over port 443, mimicking legitimate Microsoft Graph API traffic. Evasion techniques include AMSI patching via amsi.dll memory manipulation and obfuscated variable names generated from system UUIDs. The malware can enumerate Active Directory, capture keystrokes, and exfiltrate files via split HTTP POST requests.
First identified in the wild on 2024-08-15 targeting a North American energy utility, with telemetry from CrowdStrike Falcon showing 12 affected endpoints before containment. The campaign leveraged compromised Microsoft 365 accounts in India as relay points. No CVEs have been newly assigned; however, CVE-2024-38112 (Windows SmartScreen bypass) was used in conjunction with the LNK vector. Law enforcement from the U.S. CISA issued a joint advisory (AA24-256A) on 2024-09-12 detailing the threat.
Known SHA256 hash of a sample: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (file: update.ps1). Behavioral indicators include PowerShell spawning rundll32.exe with no DLL argument and outbound connections to api[.]msidentity[.]biz (resolves to 185.234.72.11). Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunSystemMaintenance is created. Mutex name GlobalMSUpdateSvc is used to prevent multiple instances.
In the observed incident, the attacker exfiltrated 2.3 GB of engineering drawings and O&M manuals over a 72-hour dwell time. Estimated remediation costs exceed $1.2 million according to the victim’s cyber insurance claim. Sectors most at risk are critical infrastructure—energy, water, and transportation—where operational technology (OT) network segmentation is weak.
Enable AMSI logging and PowerShell script block logging (MITRE ATT&CK T1562.001). Deploy the Sigma rule from Socprep (ID soc-emerging-powershell-backdoor-ps001) to detect anomalous PowerShell parent-child process trees. Apply Microsoft’s September 2024 Patch Tuesday updates for CVE-2024-38217 and CVE-2024-38112. Network defenders should block outbound connections to the IP range 185.234.72.0/24 and enforce application control policies using Windows Defender Application Control (WDAC).
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.