ATT&CKSoftwarePowerShower

PowerShower

S0441

Malware.View on attack.mitre.org

About this malware

PowerShower is a PowerShell backdoor used by Inception for initial reconnaissance and to download and execute second stage payloads.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1016
System Network Configuration Discovery

PowerShower has the ability to identify the current Windows domain of the infected host.

T1033
System Owner/User Discovery

PowerShower has the ability to identify the current user on the infected host.

T1041
Exfiltration Over C2 Channel

PowerShower has used a PowerShell document stealer module to pack and exfiltrate .txt, .pdf, .xls or .doc files smaller than 5MB that were modified during the past two days.

T1057
Process Discovery

PowerShower has the ability to deploy a reconnaissance module to retrieve a list of the active processes.

T1059.001
PowerShell

PowerShower is a backdoor written in PowerShell.

T1059.005
Visual Basic

PowerShower has the ability to save and execute VBScript.

T1070.004
File Deletion

PowerShower has the ability to remove all files created during the dropper process.

T1071.001
Web Protocols

PowerShower has sent HTTP GET and POST requests to C2 servers to send information and receive instructions.

T1082
System Information Discovery

PowerShower has collected system information on the infected host.

T1112
Modify Registry

PowerShower has added a registry key so future powershell.exe instances are spawned off-screen by default, and has removed all registry entries that are left behind during the dropper process.

T1132.001
Standard Encoding

PowerShower has the ability to encode C2 communications with base64 encoding.

T1547.001
Registry Run Keys / Startup Folder

PowerShower sets up persistence with a Registry run key.

T1560.001
Archive via Utility

PowerShower has used 7Zip to compress .txt, .pdf, .xls or .doc files prior to exfiltration.

T1564.003
Hidden Window

PowerShower has added a registry key so future powershell.exe instances are spawned with coordinates for a window position off-screen by default.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Kaspersky Cloud Atlas August 2019 Open source
    GReAT. (2019, August 12). Recent Cloud Atlas activity. Retrieved May 8, 2020.
  2. Unit 42 Inception November 2018 Open source
    Lancaster, T. (2018, November 5). Inception Attackers Target Europe with Year-old Office Vulnerability. Retrieved May 8, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.