ATT&CKSoftwarePOWERSOURCE

POWERSOURCE

S0145

Malware.View on attack.mitre.org

About this malware

POWERSOURCE is a PowerShell backdoor that is a heavily obfuscated and modified version of the publicly available tool DNS_TXT_Pwnage. It was observed in February 2017 in spearphishing campaigns against personnel involved with United States Securities and Exchange Commission (SEC) filings at various organizations. The malware was delivered when macros were enabled by the victim and a VBS script was dropped.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1012
Query Registry

POWERSOURCE queries Registry keys in preparation for setting Run keys to achieve persistence.

T1059.001
PowerShell

POWERSOURCE is a PowerShell backdoor.

T1071.004
DNS

POWERSOURCE uses DNS TXT records for C2.

T1105
Ingress Tool Transfer

POWERSOURCE has been observed being used to download TEXTMATE and the Cobalt Strike Beacon payload onto victims.

T1547.001
Registry Run Keys / Startup Folder

POWERSOURCE achieves persistence by setting a Registry Run key, with the path depending on whether the victim account has user or administrator access.

T1564.004
NTFS File Attributes

If the victim is using PowerShell 3.0 or later, POWERSOURCE writes its decoded payload to an alternate data stream (ADS) named kernel32.dll that is saved in %PROGRAMDATA%\Windows\.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Cisco DNSMessenger March 2017 Open source
    Brumaghin, E. and Grady, C.. (2017, March 2). Covert Channels and Poor Decisions: The Tale of DNSMessenger. Retrieved March 8, 2017.
  2. FireEye FIN7 March 2017 Open source
    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.