PowerPunch is a Windows malware loader associated with PowerShell-based execution and staging activity. Microsoft Threat Intelligence Center categorized it as a distinct malware family and identified it alongside QuietSieve in intrusion activity. PowerPunch is notable for executing through PowerShell and for using Base64-encoded scripts, indicating an emphasis on script-based staging and obfuscated execution. As a loader, its role is to launch or deliver follow-on payloads rather than serve as the final objective payload itself. The available reporting supports PowerShell-centric execution behavior on Windows systems, but does not provide high-confidence detail on specific delivery vectors, persistence mechanisms, or victim sectors for this family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2022, the Microsoft Threat Intelligence Center (MSTIC) categorised these payloads as distinct families, notably PowerPunch (a loader) and QuietSieve (a stealer).
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
APT19 used Base64 to obfuscate executed commands; APT32 used Invoke-Obfuscation to obfuscate PowerShell; Aquatic Panda encoded PowerShell commands in Base64; numerous groups and malware used Base64, XOR, RC4, compression, encryption, variable substitution, and other methods to obfuscate scripts and commands.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader family name used by MSTIC for a Gamaredon staging component; the report aligns it under the GammaLoad taxonomy.
Malware capable of execution through PowerShell.
Malware/backdoor capable of executing through PowerShell.
Malware that can use Base64-encoded scripts for obfuscation or execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.