PowerLess is a modular, multistage PowerShell backdoor for Windows associated with the Iranian state-backed threat actor Phosphorus, also tracked as APT35 and Charming Kitten. It executes PowerShell within a hosted .NET application rather than launching the standalone PowerShell executable, reducing visibility to security controls that monitor conventional PowerShell process execution. It supports remote command execution, termination of running processes, encrypted command-and-control communications, and the decryption and deployment of additional payloads.
PowerLess includes browser-information-stealing and keylogging modules. Its browser module reads Google Chrome and Microsoft Edge database files, stages collected information locally, and can encrypt browser databases before exfiltration. Captured keystrokes are also staged locally. Later versions incorporate Antimalware Scan Interface and Event Tracing for Windows bypasses and Telegram-based command-and-control communication. Delivery chains have used malicious Windows shortcut files to deploy encrypted payloads. Its principal functions support post-compromise access and intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cybereason researchers recently discovered a new set of tools which were developed by the Phosphorus group and incorporated into their arsenal, including a novel PowerShell backdoor dubbed PowerLess Backdoor.
In this post, we highlight some of the activities we recently observed from TunnelVision operators, focusing around exploitation of VMware Horizon Log4j vulnerabilities. TunnelVision attackers have been actively exploiting the vulnerability to run malicious PowerShell commands, deploy backdoors, create backdoor users, harvest credentials and perform lateral movement.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Agent Serpens deploys the PowerLess Trojan to execute PowerShell commands within a native .NET context.”
Although it is not encrypted, it is deobfuscated and executed in a somewhat similar manner to how PowerLess, another backdoor used by the group, executes its PowerShell payload.
In parallel, the group advanced its PowerLess backdoor from version 3.3.0 to 3.3.4, adding AMSI and ETW bypass techniques, AES-encrypted payloads delivered via malicious LNK files, and Telegram-based command-and-control communication.
Their tools include custom backdoors like FalseFont or Powerless for espionage...
21 distinct techniques documented for this family, organized by ATT&CK tactic.
TunnelVision attackers have been actively exploiting the vulnerability to run malicious PowerShell commands... Typically, the threat actor initially exploits the Log4j vulnerability to run PowerShell commands directly, and then runs further commands by means of PS reverse shells.
An Iranian state-backed hacking group tracked as APT35 (aka Phosphorus or Charming Kitten) is now deploying a new backdoor called PowerLess and developed using PowerShell.
TunnelVision attackers have been actively exploiting the vulnerability to run malicious PowerShell commands, deploy backdoors, create backdoor users, harvest credentials and perform lateral movement.
The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."
Eventually, the infection chain reaches PowerLess, a script-based component used to perform subsequent malicious activities, including data theft from the compromised system.
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
"AppleSeed has compressed collected data before exfiltration."; "APT28 used a publicly available tool to gather and compress multiple documents..."; "Aria-body has used ZIP to compress data..."; "Cadelspy...compress stolen data into a .cab file."; "Daserf hides collected data in password-protected .rar archives."; "FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration."; "Lazarus Group has compressed exfiltrated data with RAR...archive specified directories in .zip format"; "XCSSET will compress entire ~/Desktop folders..."
The PowerLess backdoor features encrypted command-and-control communication channels, and it allows executing commands and killing running processes on compromised systems.
The toolset analyzed includes extremely modular, multi-staged malware that decrypts and deploys additional payloads in several stages for the sake of both stealth and efficacy. | The threat group also used the previously unknown malware to deploy additional modules, including info stealers and keyloggers, according to a report published today by the Cybereason Nocturnus Team.
This domain was also used to host a zip file ... containing a custom backdoor ... The dropped executable contains an obfuscated version of the reverse shell as described above, beaconing to the same C2 server.
“APT29 has used multiple layers of encryption within malware to protect C2 communication… BITTER has encrypted their C2 communications… MacMa has used TLS encryption… Magic Hound has used an encrypted http proxy in C2 communications… gh0st RAT has encrypted TCP communications…”
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a tradecraft comparison rather than a Blinder Tunnel payload. It executes PowerShell commands within a .NET context without creating a PowerShell.exe process, resembling the campaign's memory-only execution wrappers.
Custom backdoor referenced as used for espionage operations; sometimes paired with destructive tooling in campaigns described.
APT35 backdoor enhanced with AMSI/ETW bypasses, AES-encrypted payload delivery via LNK files, and Telegram-based C2.
A PowerShell backdoor used by the group for persistent remote access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.