POWERSTAR, also known as CharmPower and GhostEcho, is a multi-stage PowerShell-based backdoor associated with the Iranian espionage actor Charming Kitten, also tracked as APT35 and Mint Sandstorm. It has been used in targeted intelligence-collection operations against high-value individuals and organizations, including government, policy, media, research, and other entities of strategic interest to Iran. The malware has evolved from earlier, comparatively simple PowerShell implants into a more modular framework with stronger operational security, staged in-memory execution, and resilient command-and-control design.
POWERSTAR is commonly delivered through highly tailored spearphishing and social-engineering campaigns. Observed delivery methods include malicious Office documents using macros or template injection, password-protected archives containing shortcut files, and campaigns that exploit public-facing vulnerabilities such as Microsoft Exchange and Log4Shell to execute the malware. Operators have also used cloud-hosted and decentralized infrastructure to stage payloads and support command-and-control resilience.
The malware executes primarily in memory and relies on multiple downloaded stages. Recent variants separate decryption logic from the initial loader, requiring retrieval of additional remote components before the main payload can be decrypted and run. This design improves defense evasion and also gives operators an operational kill switch if supporting infrastructure is withdrawn. POWERSTAR supports dynamic configuration updates, multiple command-and-control channels, and modular expansion through additional components.
Documented capabilities include remote execution of PowerShell and C# code, host reconnaissance, system information collection, screenshot capture, process enumeration, antivirus discovery, file crawling, persistence establishment and monitoring, and cleanup of artifacts. Persistence has been observed through startup mechanisms and Registry Run keys. Some variants monitor whether persistence artifacts remain intact and report status back to the operators. Cleanup functionality includes removal of files, processes, persistence mechanisms, and other traces, indicating deliberate anti-forensics and lifecycle management.
An IPFS-enabled variant has been observed retrieving updated command-and-control information from decentralized storage, with fallback to hardcoded infrastructure if retrieval fails. This use of IPFS and shifting delivery infrastructure reflects ongoing adaptation intended to complicate takedown and analysis. References in cleanup logic and later-stage behavior suggest POWERSTAR operates within a broader Charming Kitten malware ecosystem rather than as a standalone implant.
POWERSTAR is best characterized as a Windows-focused espionage backdoor used for post-compromise control, reconnaissance, persistence, and modular collection activities in long-running targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
January: Check Point publicly reports on the exploitation of the Log4J vulnerability by Charming Kitten, resulting in subsequent execution of POWERSTAR hosted on an Amazon S3 bucket.
updates to backdoors like POWERSTAR (also known as CharmPower or GhostEcho).
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Volexity discovered that Charming Kitten was attempting to distribute an updated version of one of their backdoors, which Volexity calls POWERSTAR (also known as CharmPower).
Volexity discovered that Charming Kitten was attempting to distribute an updated version of one of their backdoors, which Volexity calls POWERSTAR (also known as CharmPower).
“GreenCharlie’s toolset centers on a multi-stage PowerShell-based malware framework, including variants known as GORBLE, TAMECAT, and POWERSTAR.”
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Charming Kitten is known for its ability to quickly weaponize both zero-day and N-day vulnerabilities... The group extensively exploits vulnerabilities in web-facing applications, mail servers, and collaboration platforms.
Volexity works with many individuals and organizations often subjected to sophisticated and highly targeted spear-phishing campaigns... Spear-phishing campaigns now often involve individual, tailored messages that engage in dialogue with each target, sometimes over a period of several days, before a malicious link or file attachment is ever sent.
In an effort to further gain the target’s confidence, Charming Kitten continued the interaction with another benign email containing a list of questions... After multiple days of benign and seemingly legitimate interaction, Charming Kitten finally sent a “draft report”... a password-protected RAR file containing a malicious LNK file.
Level 2: Kills all malware related processes and then deletes the corresponding files; also deletes a scheduled task that was not created by any file observed by Volexity during this investigation
POWERSTAR can execute commands in two programming languages, PowerShell and CSharp... start PowerShell, CSharp Executes a code block in a new thread.
A malicious LNK file downloads the initial POWERSTAR script from a Backblaze B2 bucket, executed in memory via an obfuscated call to the Invoke-Expression alias, gcm i*x... The decrypted code is then executed in memory within the same PowerShell instance.
"Obfuscation techniques include array fragments, wildcards, and string replacement..." and "MITRE ATT&CK techniques observed include ... obfuscated files/information (T1027)."
Cleanup Modules... Level 3: Deletes all the persistence-related registry keys and corresponding files Level 4: Kills all processes whose executable resides in the directory %appdata%/Microsoft/Notepad , then deletes all files recursively in this directory
Microsoft reports Mint Sandstorm distributing OneDrive-hosted PDF files containing URLs to download a DOTM from Dropbox. Once executed, template injection is abused to execute POWERSTAR which is hosted on OneDrive.
The decrypted code is then executed in memory within the same PowerShell instance. This is the primary POWERSTAR backdoor payload. The same general technique is repeated throughout the POWERSTAR framework, with additional modules downloaded and executed in memory.
Processes ... Enumerates running processes via “tasklist”, saves to %appdata%\Microsoft\Notepad\Processes.txt and uploads to C2
When successfully executed, the primary POWERSTAR backdoor payload collects a small amount of system information from the compromised machine... System Information ... executes the systeminfo command and relays information to C2.
When successfully executed, the primary POWERSTAR backdoor payload collects a small amount of system information from the compromised machine and sends it via a POST request to the C2 address... screenshots taken by the malware can be exfiltrated via HTTP or FTP
A malicious LNK file downloads the initial POWERSTAR script from a Backblaze B2 bucket... additional modules downloaded and executed in memory.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by Charming Kitten in spear-phishing-driven espionage operations; delivered via compromised emails/fake personas and associated with Exchange exploitation.
Referenced as a related/variant family whose obfuscation style is similar to TAMECAT; no additional functional details provided in the content.
Referenced only for overlap in a key/value and YARA-rule similarity with the analyzed TAMECAT loader; no additional functional details provided in this content.
A PowerShell-based, multi-stage malware variant in GreenCharlie’s framework. Uses staged obfuscation and AES decryption/execution; described as using Invoke-Expression (iex) to run decrypted payload content, then performing C2 beaconing and encrypted/encoded host data transmission.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.