CharmPower is a modular PowerShell backdoor targeting Windows systems, associated with the Iran-linked APT35 threat group, also known as Charming Kitten and Phosphorus, and a subgroup tracked by Microsoft as Mint Sandstorm. It has been deployed following exploitation of Log4Shell (CVE-2021-44228), including attacks observed in January 2022, and through targeted phishing campaigns using remote template injection. These phishing operations have targeted individuals affiliated with prominent think tanks and universities in Israel, North America, and Europe, particularly those connected to security and policy communities.
CharmPower uses PowerShell for payload execution and command-and-control communication, with additional modules transferred through C2 using Base64 encoding. Its discovery capabilities include gathering system information through WMIC, enumerating network settings with ipconfig, and querying Windows Registry uninstall values to identify installed applications. It can exfiltrate collected data through HTTP POST requests to a hardcoded C2 endpoint or through FTP using credentials embedded in its scripts. It also supports cleanup by removing persistence-related Registry artifacts. PowerStar is a refined variant of CharmPower.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In Mid-January, the Iran-linked APT35 group has been observed leveraging the Log4Shell flaw to drop a new PowerShell backdoor tracked as CharmPower.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“PowerStar” malware—a refined variant of its established backdoor named “CharmPower.”
CharmPower is a modular backdoor written in PowerShell that this subgroup delivers in phishing campaigns that rely on template injection.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
42 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat Details and IOCs Malware: BASICSTAR, CharmPower, GORBLE, GorjolEcho, NICECURL, POWERSTAR, TAMECAT
... CharmPower ... (v1.0→v1.1) ...
CharmPower (v1.0→v1.1)
An established APT35 backdoor identified as the predecessor of PowerStar. The reference provides no further details about CharmPower's functionality or delivery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.