Research Article

Deobfuscating Multi-Stage PowerShell Malware: An Ensemble Deep Learning Approach to Dynamic API Call Sequence Analysis

20 reads
SciMatic J Cybersec Digit Forensics, 2026, 1 (1), 29-35, doi: , ISSN

Abstract

Multi-stage PowerShell malware represents a highly persistent threat in modern cyber-attacks, leveraging advanced obfuscation techniques to bypass traditional static detection engines. In this paper, we propose a novel framework for detecting and deobfuscating multi-stage PowerShell malware by performing ensemble deep learning on dynamic API call sequences. By executing samples in an instrumented sandbox, we capture the runtime invocation of Windows API calls, effectively bypassing static obfuscation layers. Our proposed ensemble model integrates Bidirectional Long Short-Term Memory (BiLSTM) networks, Gated Recurrent Units (GRU), and Convolutional Neural Networks (CNN) with an attention mechanism to extract both local spatial patterns and long-term temporal dependencies from API call sequences. Evaluated on a comprehensive dataset of 12,450 benign and malicious PowerShell scripts, our model achieves a classification accuracy of 98.7% and a false-positive rate of 0.45%. Furthermore, the framework successfully maps the sequential execution flow of highly obfuscated payloads, providing digital forensic investigators with actionable behavioral intelligence. These findings demonstrate that combining dynamic API sequence analysis with ensemble deep learning significantly enhances enterprise resilience against sophisticated fileless threats.

Keywords: digital forensics, PowerShell Malware, Dynamic API Analysis, Ensemble Deep Learning, Deobfuscation
Default avatar

Blockchain Confirmation

Loading...
If you want to upload this article to SciMatic Hybrid Blockchain, install MetaMask extension to your web browser, create a wallet and buy SCI coins at SciMatic using credit or contact your country coordinator.
One article costs 10 SCI coins to be in the Blockchain. Buy SCI Coins

Bibliographic Information

Dr. Lukas Novak, Dr. Yuki Bergström, (2026). Deobfuscating Multi-Stage PowerShell Malware: An Ensemble Deep Learning Approach to Dynamic API Call Sequence Analysis, SciMatic Journal of Cybersecurity and Digital Forensics, 1(1): 29-35
Bibtex Citation
@article{dr._lukas_novak2026sjcdf,
author = {Dr. Lukas Novak and Dr. Yuki Bergström},
title = {Deobfuscating Multi-Stage PowerShell Malware: An Ensemble Deep Learning Approach to Dynamic API Call Sequence Analysis},
journal = {SciMatic Journal of Cybersecurity and Digital Forensics},
year = {2026},
volume = {1},
number = {1},
pages = {29-35},
doi = {},
url = {https://scimatic.org/show_manuscript/8512}
}
APA Citation
Novak, D.L., Bergström, D.Y., (2026). Deobfuscating Multi-Stage PowerShell Malware: An Ensemble Deep Learning Approach to Dynamic API Call Sequence Analysis. SciMatic Journal of Cybersecurity and Digital Forensics, 1(1), 29-35. https://doi.org/

Author Information

  • To change your profile photo, login to scimatic.org, go to your profile and change the photo.
  • Provide a face photo, and not full body.
  • It is better to remove the background from your photo. Go to Remove Background and then upload to profile
  • If you are unable to login, go to Reset My Password provide your email registered with the article and get new password.
  • In case of any other problem, contact your editor directly or write to us at info @ scimatic.org