PowerLess

S1012

Malware.View on attack.mitre.org

About this malware

PowerLess is a PowerShell-based modular backdoor that has been used by Magic Hound since at least 2022.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1005
Data from Local System

PowerLess has the ability to exfiltrate data, including Chrome and Edge browser database files, from compromised machines.

T1056.001
Keylogging

PowerLess can use a module to log keystrokes.

T1059.001
PowerShell

PowerLess is written in and executed via PowerShell without using powershell.exe.

T1074.001
Local Data Staging

PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`.

T1105
Ingress Tool Transfer

PowerLess can download additional payloads to a compromised host.

T1140
Deobfuscate/Decode Files or Information

PowerLess can use base64 and AES ECB decryption prior to execution of downloaded modules.

T1217
Browser Information Discovery

PowerLess has a browser info stealer module that can read Chrome and Edge browser database files.

T1560
Archive Collected Data

PowerLess can encrypt browser database files prior to exfiltration.

T1573
Encrypted Channel

PowerLess can use an encrypted channel for C2 communications.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cybereason PowerLess February 2022 Open source
    Cybereason Nocturnus. (2022, February 1). PowerLess Trojan: Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage. Retrieved June 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.