POWERTON

S0371

Malware.View on attack.mitre.org

About this malware

POWERTON is a custom PowerShell backdoor first observed in 2018. It has typically been deployed as a late-stage backdoor by APT33. At least two variants of the backdoor have been identified, with the later version containing improved functionality.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1003.002
Security Account Manager

POWERTON has the ability to dump password hashes.

T1059.001
PowerShell

POWERTON is written in PowerShell.

T1071.001
Web Protocols

POWERTON has used HTTP/HTTPS for C2 traffic.

T1546.003
Windows Management Instrumentation Event Subscription

POWERTON can use WMI for persistence.

T1547.001
Registry Run Keys / Startup Folder

POWERTON can install a Registry Run key for persistence.

T1573.001
Symmetric Cryptography

POWERTON has used AES for encrypting C2 traffic.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye APT33 Guardrail Open source
    Ackerman, G., et al. (2018, December 21). OVERRULED: Containing a Potentially Destructive Adversary. Retrieved January 17, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.