ATT&CKSoftwarePower Loader

Power Loader

S0177

Malware.View on attack.mitre.org

About this malware

Power Loader is modular code sold in the cybercrime market used as a downloader in malware families such as Carberp, Redyms and Gapz.

Techniques used1

Procedure examples1

TechniqueProcedure example
T1055.011
Extra Window Memory Injection

Power Loader overwrites Explorer’s Shell_TrayWnd extra window memory to redirect execution to a NTDLL function that is abused to assemble and execute a return-oriented programming (ROP) chain and create a malicious thread within Explorer.exe.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. MalwareTech Power Loader Aug 2013 Open source
    MalwareTech. (2013, August 13). PowerLoader Injection – Something truly amazing. Retrieved December 16, 2017.
  2. WeLiveSecurity Gapz and Redyms Mar 2013 Open source
    Matrosov, A. (2013, March 19). Gapz and Redyms droppers based on Power Loader code. Retrieved December 16, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.