PS1

S0613

Malware.View on attack.mitre.org

About this malware

PS1 is a loader that was used to deploy 64-bit backdoors in the CostaRicto campaign.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

PS1 is distributed as a set of encrypted files and scripts.

T1055.001
Dynamic-link Library Injection

PS1 can inject its payload DLL Into memory.

T1059.001
PowerShell

PS1 can utilize a PowerShell loader.

T1105
Ingress Tool Transfer

CostaBricks can download additional payloads onto a compromised host.

T1140
Deobfuscate/Decode Files or Information

PS1 can use an XOR key to decrypt a PowerShell loader and payload binary.

Groups that use it0

None recorded.

Campaigns1

References1

  1. BlackBerry CostaRicto November 2020 Open source
    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.