Malware.View on attack.mitre.org
CharmPower is a PowerShell-based, modular backdoor that has been used by Magic Hound since at least 2022.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
CharmPower can collect data and files from a compromised host. |
| T1008 Fallback Channels |
CharmPower can change its C2 channel once every 360 loops by retrieving a new domain from the actors’ S3 bucket. |
| T1012 Query Registry |
CharmPower has the ability to enumerate `Uninstall` registry values. |
| T1016 System Network Configuration Discovery |
CharmPower has the ability to use |
| T1016.002 Wi-Fi Discovery |
CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details. |
| T1041 Exfiltration Over C2 Channel |
CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST. |
| T1047 Windows Management Instrumentation |
CharmPower can use `wmic` to gather information from a system. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
CharmPower can send victim data via FTP with credentials hardcoded in the script. |
| T1057 Process Discovery |
CharmPower has the ability to list running processes through the use of `tasklist`. |
| T1059.001 PowerShell |
CharmPower can use PowerShell for payload execution and C2 communication. |
| T1059.003 Windows Command Shell |
The C# implementation of the CharmPower command execution module can use |
| T1070.004 File Deletion |
CharmPower can delete created files from a compromised system. |
| T1071.001 Web Protocols |
CharmPower can use HTTP to communicate with C2. |
| T1082 System Information Discovery |
CharmPower can enumerate the OS version and computer name on a targeted system. |
| T1083 File and Directory Discovery |
CharmPower can enumerate drives and list the contents of the C: drive on a victim's computer. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.