Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Towards the end of 2021, multiple attacks were carried out exploiting the notorious Microsoft Exchange Server vulnerabilities chained together and referred to as ProxyShell, which ultimately enabled multiple threat actors to deploy malware on their targets’ networks. | Cybereason researchers recently discovered a new set of tools which were developed by the Phosphorus group and incorporated into their arsenal, including a novel PowerShell backdoor dubbed PowerLess Backdoor.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The APT35 group is now deploying a new PowerShell backdoor called PowerLess Backdoor using a stealthy technique to avoid detection.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
One of the IP addresses serves a domain which is being used as command and control (C2) for the recently discovered Memento Ransomware.
Below is the capabilities supported by the PowerLess backdoor: Downloading and executing additional malware and files
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously undocumented PowerShell backdoor run in a .NET context to avoid spawning powershell.exe directly. It supports downloading and executing additional payloads, encrypted C2 communications, arbitrary command execution, process killing, browser data theft, and keylogging.
A PowerShell backdoor run within a .NET context to evade detection. It supports downloading and executing additional malware and files, arbitrary command execution, process killing, encrypted C2 communications, browser data theft, and keylogging.
PowerLess Backdoor is a novel, modular PowerShell-based backdoor used by the Iranian APT group Phosphorus (APT35/Charming Kitten). It is designed for espionage, supports downloading additional payloads (such as a keylogger and info stealer), executes arbitrary commands, and evades detection by running PowerShell code within a .NET context. It establishes encrypted C2 communications and can steal browser data and log keystrokes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.