PowerCat is an open-source PowerShell implementation of Netcat used for legitimate penetration testing and malicious remote shell access on Windows systems. Attackers use it to establish outbound connections to attacker-controlled servers and expose an interactive command shell, enabling remote command execution on compromised hosts. It is a dual-use utility rather than an inherently malicious trojan.
PowerCat has been deployed during post-exploitation of vulnerable Microsoft Exchange, Windows Server Update Services (WSUS), and Sunlogin installations. In attacks exploiting WSUS vulnerability CVE-2025-59287, attackers downloaded and executed the utility to obtain an interactive Windows command shell. Sunlogin exploitation campaigns have similarly launched PowerCat reverse shells alongside other offensive tooling. Its use has been associated with Tortilla, Sofacy (APT28), and Greenbug operations, including remote access, resource discovery, and lateral movement. Exploitation and security-product disabling in these campaigns are performed by surrounding tools, not by PowerCat itself.
The PowerShell utility is distinct from the Java-based information stealer and remote access trojan also tracked as Powercat, which is distributed through fake Xeno Roblox executor packages.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
After exploiting the WSUS vulnerability, attackers deployed PowerCat, an open-source PowerShell-based Netcat utility, to establish an interactive command shell on compromised servers.
Coverage Snort SIDs: CVE-2021-26858 & CVE-2021-27065 — 57245-57246; CVE-2021-27065 — 57252-57253 | These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
Coverage Snort SIDs: CVE-2021-26855 — 57241-57244 | These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
Coverage Snort SIDs: CVE-2021-26857 — 57233-57234 | These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
Coverage Snort SIDs: CVE-2021-26858 & CVE-2021-27065 — 57245-57246 | These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Prior to this ransomware-inflicting campaign, Tortilla has been experimenting with other payloads, such as the PowerShell-based netcat clone PowerCat.
These payloads can include things like web shells and potentially other utilities like powercat... Here is a second query that is specifically looking for powercat, one of the other non-webshell based payloads
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Review Startup Apps, Task Scheduler, and HKCU\Software\Microsoft\Windows\CurrentVersion\Run for Display Calibration or another entry pointing to a Java command in AppData.
Tools discovered may be pentest-utilities, for tunneling (SOCKS or other), reconnaissance scanners, exploitation code, reverse shells, malware loaders or trojans. The tools Procdump, Nishang and Powercat have been reported to be used by the HAFNIUM threat actor group according to Microsoft.
Use of PowerShell to download and execute PowerCat for establishing reverse shell connections.
The final Java stage acts as both an information stealer and a RAT: it can collect browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and interactive PowerShell sessions.
The final Java stage acts as both an information stealer and a RAT: it can collect browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and interactive PowerShell sessions.
PowerCat can also perform port-scans, start persistent listeners, or act as a simple web server.
The exploitation has predominantly been in the form of semi-automatic installation of webshells that seems to leave backdoors for future access, or more manual by using tools to first gather credentials and system information followed by lateral movement and further compromise.
The final Java stage acts as both an information stealer and a RAT: it can collect browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and interactive PowerShell sessions.
The final Java stage acts as both an information stealer and a RAT: it can collect browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and interactive PowerShell sessions.
Tools discovered may be pentest-utilities, for tunneling (SOCKS or other), reconnaissance scanners, exploitation code, reverse shells, malware loaders or trojans.
By default, PowerCat uses TCP and reads from / writes to the console.
The PowerShell command uses “DownloadString('https://raw.githubusercontent.com/.../powercat.ps1')” before executing Powercat.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Java-based information stealer and remote access trojan delivered via trojanized fake Xeno Roblox executor packages. The final stage steals browser cookies, Roblox and Minecraft data, Discord tokens, Microsoft Store tokens, wallet information, screenshots, webcam output, keystrokes, files, and supports interactive PowerShell sessions.
Java-based multi-stage malware distributed via fake Roblox Xeno cheat packages. It performs anti-VM checks, steals browser and application data, targets gaming and cryptocurrency accounts, captures screenshots, logs keyboard and mouse activity, accesses webcams, streams the victim desktop, executes commands, transfers files, runs PowerShell, and provides an interactive remote shell.
Earlier tracking name for the same or closely related malware family; described as a stealer and RAT under active development with evolving C2 infrastructure and capabilities.
A Java-based malware family delivered via fake Xeno Executor installers targeting Roblox players. It uses a staged infection chain with an initial loader that checks for Java, launches an obfuscated Java payload, registers the victim with C2, and downloads a final payload that steals credentials, browser data, tokens, payment information, and cryptocurrency wallet data while also providing surveillance and full remote administration capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.