Malware.View on attack.mitre.org
PowerPunch is a lightweight downloader that has been used by Gamaredon Group since at least 2021.
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
PowerPunch can use Base64-encoded scripts. |
| T1059.001 PowerShell |
PowerPunch has the ability to execute through PowerShell. |
| T1105 Ingress Tool Transfer |
PowerPunch can download payloads from adversary infrastructure. |
| T1480.001 Environmental Keying |
PowerPunch can use the volume serial number from a target host to generate a unique XOR key for the next stage payload. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.