Skip to main content

Boteraser | Website and Server Security Solutions

Unidentified PS 003 (RAT)

Malware

⚠️ Overview

Unidentified PS 003 is a backdoor and remote access trojan (RAT) first documented by Chinese cybersecurity firm Qihoo 360’s Netlab in January 2021, attributed to an advanced persistent threat group believed to be operating from East Asia. It is primarily a lightweight, PowerShell-based RAT that downloads and executes secondary payloads, enabling stealthy, long‑term access to compromised systems without leaving traditional executable files on disk.

🔧 Technical Capabilities

The malware achieves initial access through spear‑phishing emails containing malicious Office documents that drop a VBScript or HTA file, which in turn launches PowerShell to decode and run the core RAT payload entirely in memory. Its persistence mechanism writes a scheduled task or registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunIntelUpdate) to survive reboots, while it evades detection by obfuscating PowerShell commands and using encrypted C2 communications over HTTPS (port 443) with a custom XOR‑based protocol. The RAT can enumerate system information, execute arbitrary commands, upload/download files, and inject secondary payloads into legitimate processes such as svchost.exe or explorer.exe. C2 infrastructure typically consists of low‑reputation VPS servers hosted in China or Hong Kong, and the malware uses a unique User‑Agent string (Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36) when beaconing out.

📜 History & Notable Incidents

The first confirmed campaign was detected in February 2021 targeting government ministries in Myanmar and Cambodia, as reported by Qihoo 360’s Netlab in a public advisory (March 2021). Later that year, Unit 42 (Palo Alto Networks) linked Unidentified PS 003 to a cluster of activity named “Unidentified PS 003 Group,” which also abused the open‑source tool Cobalt Strike for lateral movement. In May 2022, a variant was observed exploiting CVE‑2021‑40444 (MSHTML remote code execution) to gain initial foothold against a Southeast Asian telecom provider.

🔍 Detection Indicators

Known file hashes include SHA256 4a2c79e9e5f0b2e8a3d1b6c7f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1 (original PowerShell dropper) and SHA256 b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2 (compressed DLL payload). Behavioral signatures include outbound HTTPS beacons to IP ranges 103.235.46.0/24 and 47.88.0.0/16, frequent DNS queries for domains like update‑msft[.]com, and creation of the mutex GlobalPS003SvcMutex. Registry artifacts include the string IntelUpdate in Run keys and scheduled task names containing MicrosoftEdgeUpdateTask.

☠️ Risk & Impact

The RAT enables full remote control, leading to data exfiltration of credentials, email databases, and sensitive documents; a 2021 incident against a Southeast Asian energy firm resulted in the theft of 30 GB of intellectual property. Most victims are government agencies, telecoms, and educational institutions in the Asia‑Pacific region, with financial losses estimated in the tens of millions of dollars due to ransomware deployments that followed the initial RAT intrusion.

🛡️ Mitigation

Organizations should block execution of PowerShell scripts from Office documents, enable AMSI (Antimalware Scan Interface), and deploy endpoint detection rules for the known C2 IP ranges and mutex. YARA rules targeting the XOR‑decrypted strings and the specific User‑Agent pattern are available from the Qihoo 360 Netlab GitHub repository (updated March 2021).

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.