Powercat is a name used in two distinct but related contexts in intrusion activity. Most commonly, it refers to a PowerShell implementation of Netcat used as an offensive utility to establish reverse shells, execute commands, and support post-exploitation tasks on Windows systems. It has been observed in hands-on-keyboard intrusions following exploitation of internet-facing services, including Microsoft Exchange and Sunlogin, and has been used by multiple threat actors as a lightweight mechanism for unauthorized shell access, reconnaissance, and lateral movement. In these cases, Powercat functions as a semi-legitimate post-exploitation tool rather than a bespoke malware family.
The name Powercat has also been applied to a separate Java-based Windows malware family distributed through fake Roblox Xeno executor packages promoted in gaming forums and Discord communities. In that usage, Powercat is a multi-stage stealer and remote access trojan that masquerades as cheat software, checks for or installs a local Java runtime, launches obfuscated Java components, performs anti-analysis checks, establishes persistence, and retrieves additional payloads from command-and-control infrastructure. The final payload supports theft of browser cookies and stored data, Discord, Roblox, Minecraft, Microsoft Store, wallet, and payment-related information, while also enabling keylogging, screenshot capture, webcam access, desktop streaming, file transfer, PowerShell execution, and interactive remote shell access. Reporting indicates this Java-based Powercat remains under active development with evolving infrastructure and expanded functionality.
Because the same name is used for both an open-source PowerShell reverse-shell utility and a distinct Java-based criminal RAT/stealer, attribution and classification require context. Across reporting, Powercat has been associated with post-exploitation activity by diverse actors, including ransomware operators and opportunistic attackers, as well as with malware delivery through cracked or fake gaming tools targeting Windows users.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Coverage Snort SIDs: CVE-2021-26858 & CVE-2021-27065 — 57245-57246; CVE-2021-27065 — 57252-57253 | These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
Coverage Snort SIDs: CVE-2021-26855 — 57241-57244 | These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
Coverage Snort SIDs: CVE-2021-26857 — 57233-57234 | These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
Coverage Snort SIDs: CVE-2021-26858 & CVE-2021-27065 — 57245-57246 | These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
Prior to this ransomware, Tortilla has been experimenting with other payloads, such as the PowerShell-based netcat clone Powercat, which is known to provide attackers with unauthorized access to Windows machines.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Review Startup Apps, Task Scheduler, and HKCU\Software\Microsoft\Windows\CurrentVersion\Run for Display Calibration or another entry pointing to a Java command in AppData.
When executed, the reverse shell connects to the C&C server and provides the threat actor control over the infected system by providing the cmd.exe, in other words, the shell.
PowerCat is packaged as a PowerShell module. You must import the module to use its functions.
The final Java stage acts as both an information stealer and a RAT: it can collect browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and interactive PowerShell sessions.
The final Java stage acts as both an information stealer and a RAT: it can collect browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and interactive PowerShell sessions.
PowerCat can also perform port-scans, start persistent listeners, or act as a simple web server.
The final Java stage acts as both an information stealer and a RAT: it can collect browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and interactive PowerShell sessions.
The final Java stage acts as both an information stealer and a RAT: it can collect browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and interactive PowerShell sessions.
Relays in PowerCat are similar to netcat relays, but you don't have to create a file or start a second process. You can also relay data between connections of different protocols.
By default, PowerCat uses TCP and reads from / writes to the console.
PowerCat can be used to transfer files using the -SendFile and -ReceiveFile parameters.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Java-based information stealer and remote access trojan delivered via trojanized fake Xeno Roblox executor packages. The final stage steals browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and supports interactive PowerShell sessions.
Java-based multi-stage malware distributed via fake Roblox Xeno cheat packages. It performs anti-VM checks, steals browser and application data, targets gaming and cryptocurrency accounts, captures screenshots, logs keyboard and mouse activity, accesses webcams, streams the victim desktop, executes commands, transfers files, runs PowerShell, and provides an interactive remote shell.
Earlier tracking name for the same or closely related malware family; described as a stealer and RAT under active development with evolving C2 infrastructure and capabilities.
A Java-based malware family delivered via fake Xeno Executor installers targeting Roblox players. It uses a staged infection chain with an initial loader that checks for Java, launches an obfuscated Java payload, registers the victim with C2, and downloads a final payload that steals credentials, browser data, tokens, payment information, and cryptocurrency wallet data while also providing surveillance and full remote administration capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.