POWERSTAR is a multi-stage PowerShell-based malware/backdoor associated with Iranian espionage activity, particularly Charming Kitten / APT35 and related reporting on APT42 and GreenCharlie toolsets. The content states it is also known as CharmPower and GhostEcho in some reporting. It is described as part of a broader PowerShell malware framework alongside variants such as GORBLE and TAMECAT, using advanced obfuscation, layered decryption, AES-based payload protection, and in-memory execution to evade detection. Reported obfuscation techniques include array fragments, wildcards, and string replacement. The malware framework is described as collecting host details such as operating system and computer name, formatting host information into JSON, encrypting it, and sending it via HTTP POST to command-and-control infrastructure. The content also notes overlap between TAMECAT and PowerStar artifacts, including a shared value identified by Volexity in a PowerStar variant. POWERSTAR has been delivered through spear-phishing and social-engineering operations using fake personas and compromised email accounts, and the content also states Charming Kitten used Microsoft Exchange vulnerability exploitation to deliver POWERSTAR malware. Associated targeting attributed to the actor includes governments, military personnel, journalists, researchers, dissidents, and organizations in sectors such as energy, telecommunications, defense, healthcare, and academia across the Middle East, the United States, and Europe. High-confidence actor associations in the content are Charming Kitten / APT35, with additional references placing POWERSTAR within GreenCharlie’s malware framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
updates to backdoors like POWERSTAR (also known as CharmPower or GhostEcho).
updates to backdoors like POWERSTAR (also known as CharmPower or GhostEcho).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
updates to backdoors like POWERSTAR (also known as CharmPower or GhostEcho).
“GreenCharlie’s toolset centers on a multi-stage PowerShell-based malware framework, including variants known as GORBLE, TAMECAT, and POWERSTAR.”
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Charming Kitten is known for its ability to quickly weaponize both zero-day and N-day vulnerabilities... The group extensively exploits vulnerabilities in web-facing applications, mail servers, and collaboration platforms.
Multiple Iran-nexus APT groups are described as using spear-phishing: e.g., Charming Kitten uses “spear-phishing with fake personas and compromised emails… phishing via benign PDFs for credential harvesting”; several others use “spear-phishing with malicious documents/attachments/links.”
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by Charming Kitten in spear-phishing-driven espionage operations; delivered via compromised emails/fake personas and associated with Exchange exploitation.
Referenced as a related/variant family whose obfuscation style is similar to TAMECAT; no additional functional details provided in the content.
Referenced only for overlap in a key/value and YARA-rule similarity with the analyzed TAMECAT loader; no additional functional details provided in this content.
A PowerShell-based, multi-stage malware variant in GreenCharlie’s framework. Uses staged obfuscation and AES decryption/execution; described as using Invoke-Expression (iex) to run decrypted payload content, then performing C2 beaconing and encrypted/encoded host data transmission.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.