POWERTON is a PowerShell-based backdoor associated with Iranian state-linked intrusion activity, particularly operations attributed to APT33, also tracked by Microsoft as HOLMIUM and more recently as Peach Sandstorm or Refined Kitten. It has been used after successful initial compromise to provide remote access on Windows systems and support follow-on intrusion activity. Reported deployment chains include spear-phishing and cloud-to-endpoint compromise workflows in which stolen Exchange or Office 365 credentials were abused to execute malicious code through Microsoft Outlook, leading to direct execution of the POWERTON backdoor from an Outlook process. POWERTON has also been referenced as a custom dropper or backdoor used in targeting of aerospace, defense, chemical, mining, petrochemical, and satellite communications-related organizations.
The malware is implemented in PowerShell and communicates with command-and-control infrastructure over HTTP and HTTPS. Its command-and-control traffic has been reported as AES-encrypted, indicating an effort to hinder inspection and analysis. POWERTON supports persistence through multiple Windows-native mechanisms, including Registry Run autoruns and WMI-based persistence. It has also been reported to dump password hashes, indicating credential access functionality that can facilitate privilege escalation and lateral movement during broader compromise operations.
Operational reporting places POWERTON within post-compromise tradecraft used by APT33-linked operators to maintain access, expand control inside victim environments, and support longer-term espionage or destructive objectives. A related .NET payload known as POWERBAND has been described as a variant derived from earlier POWERTON tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Multiple actors and tools (e.g., APT29, APT33, FIN8, Turla, Blue Mockingbird, PoshC2, POSHSPY, RegDuke, SeaDuke) are described as using WMI event subscriptions/filters/consumers to establish persistence, including triggering at system boot or on specific process start (e.g., WINWORD.EXE).
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Multiple actors and tools (e.g., APT29, APT33, FIN8, Turla, Blue Mockingbird, PoshC2, POSHSPY, RegDuke, SeaDuke) are described as using WMI event subscriptions/filters/consumers to establish persistence, including triggering at system boot or on specific process start (e.g., WINWORD.EXE).
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The content is a catalog of malware and threat groups that encrypt command-and-control communications using algorithms such as DES, AES, RC4, XOR, Blowfish, RSA, Camellia, RC2, RC6, and custom ciphers.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom dropper used to deploy additional payloads in targeted intrusions, including campaigns against satellite communications-related targets.
Custom dropper malware used by Peach Sandstorm (APT33) to facilitate further payload delivery and persistence.
PowerShell-written malware.
Malware that establishes persistence by installing a Registry Run key.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.