ATT&CKSoftwareCharmPower

CharmPower

S0674

Malware.View on attack.mitre.org

About this malware

CharmPower is a PowerShell-based, modular backdoor that has been used by Magic Hound since at least 2022.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1005
Data from Local System

CharmPower can collect data and files from a compromised host.

T1008
Fallback Channels

CharmPower can change its C2 channel once every 360 loops by retrieving a new domain from the actors’ S3 bucket.

T1012
Query Registry

CharmPower has the ability to enumerate `Uninstall` registry values.

T1016
System Network Configuration Discovery

CharmPower has the ability to use ipconfig to enumerate system network settings.

T1016.002
Wi-Fi Discovery

CharmPower can use `netsh wlan show profiles` to list specific Wi-Fi profile details.

T1041
Exfiltration Over C2 Channel

CharmPower can exfiltrate gathered data to a hardcoded C2 URL via HTTP POST.

T1047
Windows Management Instrumentation

CharmPower can use `wmic` to gather information from a system.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

CharmPower can send victim data via FTP with credentials hardcoded in the script.

T1057
Process Discovery

CharmPower has the ability to list running processes through the use of `tasklist`.

T1059.001
PowerShell

CharmPower can use PowerShell for payload execution and C2 communication.

T1059.003
Windows Command Shell

The C# implementation of the CharmPower command execution module can use cmd.

T1070.004
File Deletion

CharmPower can delete created files from a compromised system.

T1071.001
Web Protocols

CharmPower can use HTTP to communicate with C2.

T1082
System Information Discovery

CharmPower can enumerate the OS version and computer name on a targeted system.

T1083
File and Directory Discovery

CharmPower can enumerate drives and list the contents of the C: drive on a victim's computer.

View all 24 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Check Point APT35 CharmPower January 2022 Open source
    Check Point. (2022, January 11). APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit. Retrieved January 24, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.