Malware.View on attack.mitre.org
PowerExchange is a PowerShell backdoor that has been used by OilRig since at least 2023 including against government targets in the Middle East.
| Technique | Procedure example |
|---|---|
| T1041 Exfiltration Over C2 Channel |
PowerExchange can exfiltrate files via its email C2 channel. |
| T1059.001 PowerShell |
PowerExchange can use PowerShell to execute commands received from C2. |
| T1071.003 Mail Protocols |
PowerExchange can receive and send back the results of executed C2 commands through email. |
| T1105 Ingress Tool Transfer |
PowerExchange can decode Base64-encoded files and call `WriteAllBytes` to write the files to compromised hosts. |
| T1140 Deobfuscate/Decode Files or Information |
PowerExchange can decode and decrypt C2 commands received via email. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.