Empire, also known as PowerShell Empire, is a publicly available post-exploitation and adversary-emulation framework used by penetration testers, red teams, and malicious threat actors. PowerShell and Python implementations have been observed in adversary operations. Its agents provide interactive remote access and command execution, with stagers retrieving and executing agents on compromised systems.
Empire includes a Mimikatz implementation for extracting credentials from memory, Kerberoasting functionality for obtaining crackable service-ticket material, and modules for collecting private keys and saved session information. It supports pass-the-hash authentication, process injection, local privilege-escalation exploits, and a limited set of exploits against remote SMB, JBoss, and Jenkins services. With sufficient permissions, it can create local and domain accounts to maintain access. Observed deployment chains have used reflective in-memory loading, script obfuscation, and PowerShell execution through .NET to evade security controls.
Empire has been used by APT28, APT19, CopyKittens, DarkHydrus, Frankenstein, WIRTE, and Wizard Spider, as well as ransomware operators. It has appeared as a late-stage payload in spear-phishing campaigns using malicious Office documents and exploitation of CVE-2021-40444, including attacks against government officials and defense interests in Western Asia and Eastern Europe. Its documented Windows capabilities particularly support credential access, persistence, and lateral movement within enterprise and Active Directory environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-46604 allows remote attackers with network access to a broker to execute arbitrary shell commands. This is achieved by exploiting serialized class types within the OpenWire protocol, which, in turn, leads to the broker instantiating any class available on the classpath.
Attacks began with spear-phishing emails that delivered an Excel downloader containing a remote code execution exploit (CVE-2021-40444). This led to the installation of a second-stage downloader, followed by Graphite and a secondary payload—PowerShell Empire.
25 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CopyKittens has used Metasploit and Empire for post-exploitation activities.
CopyKittens has used Metasploit and Empire for post-exploitation activities.
CopyKittens has used Metasploit and Empire for post-exploitation activities.
CopyKittens has used Metasploit and Empire for post-exploitation activities.
As of 2021, APT28 has been observed using commercially available code repositories, and post-exploit frameworks such as Empire. This included the use of Powershell Empire, in addition to Python versions of Empire.
CopyKittens has used Metasploit and Empire for post-exploitation activities.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
PSinjectの仕組み自体は以前実装したことがあり、Unmanaged Codeから.NET CLRを起動し、CLR経由でManaged Codeを実行する
Denis exploits a security vulnerability to load a fake DLL and execute its code. Empire contains modules that can discover and exploit various DLL hijacking opportunities. PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Adversaries may create a local account to maintain access to victim systems. ... Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Adversaries may create a domain account to maintain access to victim systems. With a sufficient level of access, the net user /add /domain command can be used to create a domain account.
The follow-up malware will override the CLSID '{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}' to gain persistence in the victims' system, performing a COM Hijacking technique.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ReflectivePick allows PowerShell Empire to inject and bootstrap PowerShell into any running process... Empire allows you to inject an agent into any process by remotely bootstrapping PowerShell.
The follow-up malware will override the CLSID '{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}' to gain persistence in the victims' system, performing a COM Hijacking technique.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
ReflectivePick allows PowerShell Empire to inject and bootstrap PowerShell into any running process... Empire allows you to inject an agent into any process by remotely bootstrapping PowerShell.
Denis exploits a security vulnerability to load a fake DLL and execute its code. Empire contains modules that can discover and exploit various DLL hijacking opportunities. PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password, from the operating system and software.
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
SMB-based lateral generally starts by copying a payload to the remote target. | Unfortunately, this is where SMB steps in and provides options for abuse.
Most cyber activity by malicious actors requires infrastructure like servers on the internet. Some APT groups used several thousand Command and Control (C2) servers over the years. | Also, this article covers only HTTP(S) based infrastructure.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a historical tool used alongside SystemBC by VICE SPIDER, not as a confirmed tool in this intrusion.
Offensive framework used for the campaign’s final staging and remote-control capabilities. Graphite delivers an Empire DLL launcher, which starts the .NET runtime and executes a C# PowerShell stager without requiring PowerShell.exe. A subsequent obfuscated HTTP stager downloads, decrypts, and executes an Empire agent. The chain also supports COM-hijacking persistence. The campaign’s association with APT28 remains tentative.
Post-exploitation framework previously distributed via SocGholish.
Named malware/tool family deployed via SocGholish.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.