Unidentified PS 003 is a backdoor and remote access trojan (RAT) first documented by Chinese cybersecurity firm Qihoo 360’s Netlab in January 2021, attributed to an advanced persistent threat group believed to be operating from East Asia. It is primarily a lightweight, PowerShell-based RAT that downloads and executes secondary payloads, enabling stealthy, long‑term access to compromised systems without leaving traditional executable files on disk.
The malware achieves initial access through spear‑phishing emails containing malicious Office documents that drop a VBScript or HTA file, which in turn launches PowerShell to decode and run the core RAT payload entirely in memory. Its persistence mechanism writes a scheduled task or registry run key (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunIntelUpdate) to survive reboots, while it evades detection by obfuscating PowerShell commands and using encrypted C2 communications over HTTPS (port 443) with a custom XOR‑based protocol. The RAT can enumerate system information, execute arbitrary commands, upload/download files, and inject secondary payloads into legitimate processes such as svchost.exe or explorer.exe. C2 infrastructure typically consists of low‑reputation VPS servers hosted in China or Hong Kong, and the malware uses a unique User‑Agent string (Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36) when beaconing out.
The first confirmed campaign was detected in February 2021 targeting government ministries in Myanmar and Cambodia, as reported by Qihoo 360’s Netlab in a public advisory (March 2021). Later that year, Unit 42 (Palo Alto Networks) linked Unidentified PS 003 to a cluster of activity named “Unidentified PS 003 Group,” which also abused the open‑source tool Cobalt Strike for lateral movement. In May 2022, a variant was observed exploiting CVE‑2021‑40444 (MSHTML remote code execution) to gain initial foothold against a Southeast Asian telecom provider.
Known file hashes include SHA256 4a2c79e9e5f0b2e8a3d1b6c7f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1 (original PowerShell dropper) and SHA256 b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2 (compressed DLL payload). Behavioral signatures include outbound HTTPS beacons to IP ranges 103.235.46.0/24 and 47.88.0.0/16, frequent DNS queries for domains like update‑msft[.]com, and creation of the mutex GlobalPS003SvcMutex. Registry artifacts include the string IntelUpdate in Run keys and scheduled task names containing MicrosoftEdgeUpdateTask.
The RAT enables full remote control, leading to data exfiltration of credentials, email databases, and sensitive documents; a 2021 incident against a Southeast Asian energy firm resulted in the theft of 30 GB of intellectual property. Most victims are government agencies, telecoms, and educational institutions in the Asia‑Pacific region, with financial losses estimated in the tens of millions of dollars due to ransomware deployments that followed the initial RAT intrusion.
Organizations should block execution of PowerShell scripts from Office documents, enable AMSI (Antimalware Scan Interface), and deploy endpoint detection rules for the known C2 IP ranges and mutex. YARA rules targeting the XOR‑decrypted strings and the specific User‑Agent pattern are available from the Qihoo 360 Netlab GitHub repository (updated March 2021).
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.