POWERSTAR, also known as CharmPower, is a modular, multi-stage PowerShell backdoor used by the Iran-linked cyberespionage actor Charming Kitten (APT35). Observed since at least 2021, it targets Windows systems and enables remote execution of PowerShell and C# code, system reconnaissance, and intelligence collection. Its modules support screenshot capture, process enumeration, antivirus discovery, system-information collection, file crawling, persistence monitoring, and cleanup of intrusion artifacts.
POWERSTAR has been delivered through tailored spearphishing involving journalist impersonation and prolonged trust-building conversations. Observed payloads include password-protected archives containing malicious Windows shortcuts, macro-enabled Office documents, and documents abusing remote template injection. It has also been deployed following exploitation of Log4Shell. A documented campaign targeted a journalist who had written about Iran, using a purported draft report as the lure.
The malware downloads encrypted stages and supporting scripts from cloud-hosted infrastructure, decrypts payloads with AES, and executes them in memory. Remotely hosted decryption logic impedes analysis and allows operators to disable execution by withdrawing the required resource. POWERSTAR sends collected host information to command-and-control infrastructure over HTTP POST and supports dynamic configuration changes, encryption-key updates, multiple communication channels, and additional downloadable modules. An IPFS-enabled variant retrieves updated command-and-control information from decentralized storage and falls back to a hardcoded address when retrieval fails.
Persistence mechanisms include startup execution and Registry Run keys. Dedicated monitoring modules check whether persistence artifacts remain intact, while cleanup modules can terminate processes, delete files, remove persistence, and eliminate other operational artifacts. These features support sustained espionage access while reducing traces of the intrusion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
January: Check Point publicly reports on the exploitation of the Log4J vulnerability by Charming Kitten, resulting in subsequent execution of POWERSTAR hosted on an Amazon S3 bucket.
updates to backdoors like POWERSTAR (also known as CharmPower or GhostEcho).
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This deceptive draft report came as a password-protected RAR file that embedded a harmful LNK file designed to deploy the “PowerStar” malware—a refined variant of its established backdoor named “CharmPower.”
Volexity discovered that Charming Kitten was attempting to distribute an updated version of one of their backdoors, which Volexity calls POWERSTAR (also known as CharmPower).
“GreenCharlie’s toolset centers on a multi-stage PowerShell-based malware framework, including variants known as GORBLE, TAMECAT, and POWERSTAR.”
Charming Kitten... specializes in espionage through spear-phishing... to deliver POWERSTAR malware, exploiting Microsoft Exchange vulnerabilities...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Charming Kitten is known for its ability to quickly weaponize both zero-day and N-day vulnerabilities... The group extensively exploits vulnerabilities in web-facing applications, mail servers, and collaboration platforms.
Volexity works with many individuals and organizations often subjected to sophisticated and highly targeted spear-phishing campaigns... Spear-phishing campaigns now often involve individual, tailored messages that engage in dialogue with each target, sometimes over a period of several days, before a malicious link or file attachment is ever sent.
In an effort to further gain the target’s confidence, Charming Kitten continued the interaction with another benign email containing a list of questions... After multiple days of benign and seemingly legitimate interaction, Charming Kitten finally sent a “draft report”... a password-protected RAR file containing a malicious LNK file.
Level 2: Kills all malware related processes and then deletes the corresponding files; also deletes a scheduled task that was not created by any file observed by Volexity during this investigation
POWERSTAR can execute commands in two programming languages, PowerShell and CSharp... start PowerShell, CSharp Executes a code block in a new thread.
A malicious LNK file downloads the initial POWERSTAR script from a Backblaze B2 bucket, executed in memory via an obfuscated call to the Invoke-Expression alias, gcm i*x... The decrypted code is then executed in memory within the same PowerShell instance.
"Obfuscation techniques include array fragments, wildcards, and string replacement..." and "MITRE ATT&CK techniques observed include ... obfuscated files/information (T1027)."
Cleanup Modules... Level 3: Deletes all the persistence-related registry keys and corresponding files Level 4: Kills all processes whose executable resides in the directory %appdata%/Microsoft/Notepad , then deletes all files recursively in this directory
Microsoft reports Mint Sandstorm distributing OneDrive-hosted PDF files containing URLs to download a DOTM from Dropbox. Once executed, template injection is abused to execute POWERSTAR which is hosted on OneDrive.
The decrypted code is then executed in memory within the same PowerShell instance. This is the primary POWERSTAR backdoor payload. The same general technique is repeated throughout the POWERSTAR framework, with additional modules downloaded and executed in memory.
Processes ... Enumerates running processes via “tasklist”, saves to %appdata%\Microsoft\Notepad\Processes.txt and uploads to C2
When successfully executed, the primary POWERSTAR backdoor payload collects a small amount of system information from the compromised machine... System Information ... executes the systeminfo command and relays information to C2.
When successfully executed, the primary POWERSTAR backdoor payload collects a small amount of system information from the compromised machine and sends it via a POST request to the C2 address... screenshots taken by the malware can be exfiltrated via HTTP or FTP
A malicious LNK file downloads the initial POWERSTAR script from a Backblaze B2 bucket... additional modules downloaded and executed in memory.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by Charming Kitten in spear-phishing-driven espionage operations; delivered via compromised emails/fake personas and associated with Exchange exploitation.
Referenced as a related/variant family whose obfuscation style is similar to TAMECAT; no additional functional details provided in the content.
Referenced only for overlap in a key/value and YARA-rule similarity with the analyzed TAMECAT loader; no additional functional details provided in this content.
A PowerShell-based, multi-stage malware variant in GreenCharlie’s framework. Uses staged obfuscation and AES decryption/execution; described as using Invoke-Expression (iex) to run decrypted payload content, then performing C2 beaconing and encrypted/encoded host data transmission.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.