BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

PS1Bot Malware Targets Crypto Wallets via New 2025 Malvertising Campaign

PS1Bot Malware Campaign Uses Malvertising to Target Cryptocurrency Users with Advanced Stealing and Persistence Techniques

  • Researchers identified a new malvertising campaign spreading the modular PS1Bot Malware.
  • PS1Bot can steal data, log keystrokes, perform reconnaissance, and maintain access to infected systems.
  • The malware uses in-memory execution to avoid leaving evidence and is linked to PowerShell and C# code.
  • Attackers deliver the malware through fake ads and compromised search results, targeting users interested in cryptocurrency.
  • Google has introduced AI tools using large language models to better detect invalid ad traffic and reduce threats.

Cybersecurity researchers have detected a new digital attack distributing a malware framework called PS1Bot using online advertisements. The campaign has been ongoing since early 2025, targeting users through deceptive ads and search links to install PS1Bot, which allows attackers to steal information and gain long-term system access.

- Advertisement -

PS1Bot carries out several malicious actions, including keylogging, taking screenshots, collecting sensitive data, and maintaining access on infected devices. Cisco Talos researchers say the malware works in stages and uses both PowerShell and C# to execute its modules without saving files to disk, reducing its forensic footprint.

“PS1Bot features a modular design, with several modules delivered used to perform a variety of malicious activities on infected systems, including information theft, keylogging, reconnaissance, and the establishment of persistent system access,” stated researchers Edmund Brumaghin and Jordyn Dunk. They noted that the attack begins when a user downloads a compressed ZIP archive from a malicious ad or search link containing JavaScript, which then downloads more code and executes a PowerShell script to contact remote servers.

The malware can detect antivirus tools, steal wallet and password data, take screenshots, log keystrokes, and create scripts that automatically run whenever the system restarts. “The information stealer module implementation leverages wordlists embedded into the stealer to enumerate files containing passwords and seed phrases that can be used to access cryptocurrency wallets, which the stealer also attempts to exfiltrate from infected systems,” Cisco Talos noted. The group behind PS1Bot has used similar tactics and code to previous attacks involving Ransomware and the Skitnet (also known as Bossnet) malware.

The flexible construction of PS1Bot allows attackers to quickly update modules or add new features for future campaigns. This threat highlights ongoing risks in the cryptocurrency space, as criminals remain focused on targeting wallet credentials and sensitive personal information through highly adaptive malware.

- Advertisement -

Meanwhile, Google says it is using Artificial Intelligence and large language models to improve detection of fraudulent ad activity. In a recent blog post, Google reported that its new AI-driven methods have improved content review and led to a 40% reduction in invalid traffic caused by deceptive or disruptive ads. More details are available in their announcement on fighting invalid ad traffic.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Top Nvidia Bear Turns Bullish, Sets $300 Stock Target

Prominent bearish analyst Gil Luria of D.A Davidson has reversed his long-standing negative position...

Andrew Yang’s Firm Acquires Crypto Helium Mobile

Noble Mobile, led by Andrew Yang, has acquired Helium Mobile, the service provider built...

ECB Opens Call to Help Build Tokenized Finance Ecosystem

The European Central Bank is seeking participants for its Appia contact group to design...

Ethereum Outperforms Bitcoin Amid $800M Wipeout

Leveraged crypto traders suffered nearly $800 million in liquidations over 24 hours as Bitcoin’s...

Strategy Sells 32 Bitcoin to Pay $2.5M Preferred Dividend

Strategy sold 32 Bitcoin, representing just 0.004% of its massive 843,706 BTC holdings, to...

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Key TakeawaysA Deep Dive into the Top Bitcoin Casinos of 2025Bitcoin Casino Comparison Table1. Stake.com: Best for Variety & Integrated Sports Betting2. BC.Game: Best...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading