ATT&CKSoftwarePowerPunch

PowerPunch

S0685

Malware.View on attack.mitre.org

About this malware

PowerPunch is a lightweight downloader that has been used by Gamaredon Group since at least 2021.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1027.010
Command Obfuscation

PowerPunch can use Base64-encoded scripts.

T1059.001
PowerShell

PowerPunch has the ability to execute through PowerShell.

T1105
Ingress Tool Transfer

PowerPunch can download payloads from adversary infrastructure.

T1480.001
Environmental Keying

PowerPunch can use the volume serial number from a target host to generate a unique XOR key for the next stage payload.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft Actinium February 2022 Open source
    Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.