Cybereason Nocturnus. (2022, February 1). PowerLess Trojan: Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage. Retrieved June 1, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwarePowerLess | PowerLess has the ability to exfiltrate data, including Chrome and Edge browser database files, from compromised machines. |
| T1056.001 Keylogging |
MalwarePowerLess | PowerLess can use a module to log keystrokes. |
| T1059.001 PowerShell |
MalwarePowerLess | PowerLess is written in and executed via PowerShell without using powershell.exe. |
| T1074.001 Local Data Staging |
MalwarePowerLess | PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`. |
| T1105 Ingress Tool Transfer |
MalwarePowerLess | PowerLess can download additional payloads to a compromised host. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePowerLess | PowerLess can use base64 and AES ECB decryption prior to execution of downloaded modules. |
| T1190 Exploit Public-Facing Application |
GroupMagic Hound | Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379). |
| T1217 Browser Information Discovery |
MalwarePowerLess | PowerLess has a browser info stealer module that can read Chrome and Edge browser database files. |
| T1560 Archive Collected Data |
MalwarePowerLess | PowerLess can encrypt browser database files prior to exfiltration. |
| T1573 Encrypted Channel |
MalwarePowerLess | PowerLess can use an encrypted channel for C2 communications. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.