CyberSecurityBoardThreat Intel · CVEs · Products

Tag: PowerShell

Malware

ChocoShell PowerShell Stealer

In-memory PowerShell stealer that collects Microsoft 365 and Azure AD tokens from the Token Broker cache, enabling session replay.

Azure AD ChocoShell PowerShell token theft
August 1, 2026
Malware

SCOUTCURL: PowerShell Reconnaissance Script

SCOUTCURL is a PowerShell script used by UAC-0145 to perform basic reconnaissance by harvesting details about infected machines.

malware PowerShell reconnaissance SCOUTCURL
July 19, 2026
Malware

TookPS PowerShell Downloader

TookPS is a PowerShell downloader used as the initial payload for OkoBot. It has been active since March 2025, delivered via fake…

downloader malware PowerShell SSH
July 15, 2026