ATT&CKSoftwarePowerExchange

PowerExchange

S1173

Malware.View on attack.mitre.org

About this malware

PowerExchange is a PowerShell backdoor that has been used by OilRig since at least 2023 including against government targets in the Middle East.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1041
Exfiltration Over C2 Channel

PowerExchange can exfiltrate files via its email C2 channel.

T1059.001
PowerShell

PowerExchange can use PowerShell to execute commands received from C2.

T1071.003
Mail Protocols

PowerExchange can receive and send back the results of executed C2 commands through email.

T1105
Ingress Tool Transfer

PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts.

T1140
Deobfuscate/Decode Files or Information

PowerExchange can decode and decrypt C2 commands received via email.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Crambus OCT 2023 Open source
    Symantec Threat Hunter Team. (2023, October 19). Crambus: New Campaign Targets Middle Eastern Government. Retrieved November 27, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.