Psshell
Overview
Executive Summary
PSShell refers to a category of offensive PowerShell scripts and frameworks (such as Nishang or Empire modules) designed to establish a remote, interactive command shell on a compromised Windows system. While PowerShell is a legitimate administrative tool, "PSShell" variants are specifically weaponized to evade detection, bypass execution policies, and provide threat actors with a powerful "Living off the Land" (LotL) mechanism for post-exploitation, lateral movement, and data exfiltration.Infection Vector and Technical Capabilities
PSShell scripts are rarely the initial infection vector. They are typically executed by an initial dropper (like a malicious macro) or deployed by an attacker who has already compromised an endpoint via RDP brute-forcing or vulnerability exploitation. Once deployed, PSShell frameworks exhibit advanced offensive capabilities:- Fileless Execution: PSShells are often executed entirely in memory using "Download Cradles" (e.g., `Invoke-Expression (New-Object Net.WebClient).DownloadString(...)`). This allows the attacker to establish a reverse shell without ever writing a `.ps1` script file to the hard drive, evading many traditional antivirus scanners.
- AMSI Evasion: Modern PSShell frameworks incorporate code specifically designed to hook and bypass the Windows Anti-Malware Scan Interface (AMSI), preventing Windows Defender from scanning the malicious PowerShell commands as they are executed.
- Post-Exploitation Framework: Once the shell is established, the attacker has unrestricted command-line access to the system. They can utilize built-in PowerShell cmdlets to dump credentials (e.g., Mimikatz modules), enumerate Active Directory, and pivot to other systems on the network.
Threat Assessment
The detection of an unauthorized PSShell is a critical incident indicating that an attacker has achieved interactive, command-line control over the endpoint. It signifies a mature compromise where the adversary is actively navigating the network and likely preparing for a larger objective, such as ransomware deployment or data theft.Incident Response and Remediation
- Behavioral Monitoring (EDR and Script Block Logging): Detection relies heavily on EDR telemetry and Windows Event Log 4104 (Script Block Logging). Analysts must review these logs to reconstruct the commands executed by the attacker during the PSShell session.
- Immediate Network Isolation: The endpoint must be isolated instantly to severe the reverse shell connection and halt the attacker's lateral movement.
- Total Re-imaging: Because the attacker had interactive command-line access, they could have established deep, secondary persistence mechanisms (like WMI event subscriptions or modified registry keys) that are difficult to uncover. A complete bare-metal wipe and re-image is required, alongside a global password reset.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1059.001 T1059 T1562.001 T1071.001
Tactical Mitigations
Based on the techniques used by this family, consider the following defensive strategies:
- T1059: Restrict execution of scripting languages such as PowerShell, VBScript, or Python to authorized administrators. Enforce Script Block Logging.
- T1059.001: Restrict execution of PowerShell. Enforce PowerShell Constrained Language Mode and Script Block Logging.
- T1071.001: Implement web filtering and SSL/TLS inspection to detect malicious command and control (C2) traffic hiding in HTTP/HTTPS.
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_PSSHELL {
meta:
description = "Detects Psshell (ransomware)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "psshell" ascii wide nocase
$s2 = "hacktool.psshell" ascii wide nocase
$s3 = "riskware.powershell" ascii wide nocase
$s4 = "trojan.powershell.reverseshell" ascii wide nocase
$s5 = "nishang" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Psshell Activity
id: 9f9b5b106f0ca75dcf7635413d052097
status: experimental
description: Detects generic indicators of the psshell malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*psshell*"
- "*hacktool.psshell*"
- "*riskware.powershell*"
- "*trojan.powershell.reverseshell*"
- "*nishang*"
condition: selection
level: mediumReferences & External Analysis
- Search "psshell" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Psshell Ransomware from Windows?
Manual removal of Psshell is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Psshell a virus or a Ransomware?
Psshell is classified as a Ransomware. Unlike traditional viruses that infect files, modern malware like Psshell typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Psshell infection?
Symptoms of Psshell can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: ransomware)
Explore other malware families in the same category:
Protect Your Network Against Ransomwares
Want to prevent Psshell and similar threats from compromising your organization? Read our comprehensive defensive guide: Ransomware Protection Guide.
Machine-readable
Get this profile as JSON: https://jordan123234-malware-families-explorer.static.hf.space/api/psshell.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.