ATT&CKReferencesCybereason PowerLess February 2022

Cybereason PowerLess February 2022

Cybereason Nocturnus. (2022, February 1). PowerLess Trojan: Iranian APT Phosphorus Adds New PowerShell Backdoor for Espionage. Retrieved June 1, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePowerLess

PowerLess has the ability to exfiltrate data, including Chrome and Edge browser database files, from compromised machines.

T1056.001
Keylogging
MalwarePowerLess

PowerLess can use a module to log keystrokes.

T1059.001
PowerShell
MalwarePowerLess

PowerLess is written in and executed via PowerShell without using powershell.exe.

T1074.001
Local Data Staging
MalwarePowerLess

PowerLess can stage stolen browser data in `C:\\Windows\\Temp\\cup.tmp` and keylogger data in `C:\\Windows\\Temp\\Report.06E17A5A-7325-4325-8E5D-E172EBA7FC5BK`.

T1105
Ingress Tool Transfer
MalwarePowerLess

PowerLess can download additional payloads to a compromised host.

T1140
Deobfuscate/Decode Files or Information
MalwarePowerLess

PowerLess can use base64 and AES ECB decryption prior to execution of downloaded modules.

T1190
Exploit Public-Facing Application
GroupMagic Hound

Magic Hound has exploited the Log4j utility (CVE-2021-44228), on-premises MS Exchange servers via "ProxyShell" (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), and Fortios SSL VPNs (CVE-2018-13379).

T1217
Browser Information Discovery
MalwarePowerLess

PowerLess has a browser info stealer module that can read Chrome and Edge browser database files.

T1560
Archive Collected Data
MalwarePowerLess

PowerLess can encrypt browser database files prior to exfiltration.

T1573
Encrypted Channel
MalwarePowerLess

PowerLess can use an encrypted channel for C2 communications.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.