Malware.View on attack.mitre.org
PowerLess is a PowerShell-based modular backdoor that has been used by Magic Hound since at least 2022.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
PowerLess has the ability to exfiltrate data, including Chrome and Edge browser database files, from compromised machines. |
| T1056.001 Keylogging |
PowerLess can use a module to log keystrokes. |
| T1059.001 PowerShell |
PowerLess is written in and executed via PowerShell without using powershell.exe. |
| T1074.001 Local Data Staging |
PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`. |
| T1105 Ingress Tool Transfer |
PowerLess can download additional payloads to a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
PowerLess can use base64 and AES ECB decryption prior to execution of downloaded modules. |
| T1217 Browser Information Discovery |
PowerLess has a browser info stealer module that can read Chrome and Edge browser database files. |
| T1560 Archive Collected Data |
PowerLess can encrypt browser database files prior to exfiltration. |
| T1573 Encrypted Channel |
PowerLess can use an encrypted channel for C2 communications. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.