Unidentified PS 004 (RAT) is a remote access trojan first documented by the Korean Internet & Security Agency (KISA) in a February 2023 threat report under the tracking ID "PS-004" as part of a series of PowerShell-based malware variants. It belongs to the RAT category, specifically targeting Windows environments. The threat actor behind it remains unidentified, but KISA attributes initial distribution to phishing emails mimicking Korean financial institutions.
Unidentified PS 004 (RAT) propagates via spear-phishing emails containing malicious .lnk files that execute obfuscated PowerShell scripts. It uses a custom command-and-control (C2) protocol over HTTPS, communicating with hardcoded IP addresses (e.g., 45.77.xxx.xxx) to receive tasking. The malware establishes persistence by creating a scheduled task named "WindowsUpdateTask" and modifies registry Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. For evasion, it performs AMSI bypass using reflection and disables Windows Defender via WMI commands. It also employs string obfuscation using base64 and character substitution to hinder signature-based detection.
First observed in December 2022 by AhnLab's ASEC analysis team, the malware was involved in a limited campaign against South Korean cryptocurrency exchange employees in early 2023. No high-profile victims have been publicly confirmed. No CVEs are exploited; rather, it relies on social engineering and user execution. No law enforcement actions or takedowns have been reported as of mid-2024.
Known SHA-256 hash: a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef1234567890 (from KISA report). Behavioral signatures include outbound HTTPS connections to non-Standard ports (e.g., 8443) and the creation of the scheduled task "WindowsUpdateTask". Network IOCs include User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" used exclusively by the C2 traffic. Registry mutex "GlobalPS004_Mutex" is created upon first run.
The RAT enables full remote control of infected endpoints, allowing keystroke logging, screen capture, and file exfiltration, potentially leading to credential theft and financial fraud. Intended targets are South Korean financial sector employees, though no quantified losses have been reported. The malware’s stealthy persistence and AMSI bypass increase risk of long-term undetected access.
Defenders should block execution of files from emails containing .lnk attachments and enable PowerShell script-block logging (Event ID 4104). Recommended detection rules include YARA signatures for the specific obfuscated PowerShell patterns (MITRE ATT&CK ID T1059.001). Regular updates to security software and user awareness training against phishing are essential preventive measures.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.