PS1Bot Malware Targets Crypto Wallets via New 2025 Malvertising Campaign

PS1Bot Malware Campaign Uses Malvertising to Target Cryptocurrency Users with Advanced Stealing and Persistence Techniques

  • Researchers identified a new malvertising campaign spreading the modular PS1Bot Malware.
  • PS1Bot can steal data, log keystrokes, perform reconnaissance, and maintain access to infected systems.
  • The malware uses in-memory execution to avoid leaving evidence and is linked to PowerShell and C# code.
  • Attackers deliver the malware through fake ads and compromised search results, targeting users interested in cryptocurrency.
  • Google has introduced AI tools using large language models to better detect invalid ad traffic and reduce threats.

Cybersecurity researchers have detected a new digital attack distributing a malware framework called PS1Bot using online advertisements. The campaign has been ongoing since early 2025, targeting users through deceptive ads and search links to install PS1Bot, which allows attackers to steal information and gain long-term system access.

- Advertisement -

PS1Bot carries out several malicious actions, including keylogging, taking screenshots, collecting sensitive data, and maintaining access on infected devices. Cisco Talos researchers say the malware works in stages and uses both PowerShell and C# to execute its modules without saving files to disk, reducing its forensic footprint.

“PS1Bot features a modular design, with several modules delivered used to perform a variety of malicious activities on infected systems, including information theft, keylogging, reconnaissance, and the establishment of persistent system access,” stated researchers Edmund Brumaghin and Jordyn Dunk. They noted that the attack begins when a user downloads a compressed ZIP archive from a malicious ad or search link containing JavaScript, which then downloads more code and executes a PowerShell script to contact remote servers.

The malware can detect antivirus tools, steal wallet and password data, take screenshots, log keystrokes, and create scripts that automatically run whenever the system restarts. “The information stealer module implementation leverages wordlists embedded into the stealer to enumerate files containing passwords and seed phrases that can be used to access cryptocurrency wallets, which the stealer also attempts to exfiltrate from infected systems,” Cisco Talos noted. The group behind PS1Bot has used similar tactics and code to previous attacks involving Ransomware and the Skitnet (also known as Bossnet) malware.

The flexible construction of PS1Bot allows attackers to quickly update modules or add new features for future campaigns. This threat highlights ongoing risks in the cryptocurrency space, as criminals remain focused on targeting wallet credentials and sensitive personal information through highly adaptive malware.

Meanwhile, Google says it is using Artificial Intelligence and large language models to improve detection of fraudulent ad activity. In a recent blog post, Google reported that its new AI-driven methods have improved content review and led to a 40% reduction in invalid traffic caused by deceptive or disruptive ads. More details are available in their announcement on fighting invalid ad traffic.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

Stay in the Loop

Get exclusive crypto insights, breaking news, and market analysis delivered straight to your inbox. No fluff, just facts.

    1 Email per day. Unsubscribe at any time.

    - Advertisement -

    Latest News

    Thailand Launches TouristDigiPay for Crypto-to-Baht Conversion

    Thailand is allowing foreign tourists to convert cryptocurrency to its local currency using a...

    The 2nd Edition of the CoinFerenceX Decentralized Web3 Summit: Builders, Investors, and Developers Meet Again to Shape The Web Space

    Singapore is the global blockchain hub, and it is hosting the upcoming CoinFerenceX web3...

    Bitcoin Slides Below $115K as Markets Await Powell’s Jackson Hole Speech

    Bitcoin dropped below $115,000 after setting a record high of more than $124,000 earlier...

    Dogecoin Plunges 4% to $0.22 as Liquidations Top $1B Amid Volatility

    Dogecoin declined by 4% overnight, falling from $0.23 to $0.22 amid heavy trading and...

    SEC Delays Trump’s Truth Social Bitcoin, Ethereum ETF Decision

    The U.S. Securities and Exchange Commission delayed its decision on the Truth Social Bitcoin...

    Must Read

    18 Countries With No Privacy Laws According To UN (List)

    Privacy laws are legal frameworks designed to protect personal data from unauthorized access, misuse, or disclosure.Lack of privacy laws can lead to misuse of...