POWERTRASH is a heavily obfuscated, PowerShell-based in-memory loader used by FIN7, also tracked by Microsoft as Sangria Tempest/ELBRUS. It is described as being adapted from the PowerSploit framework and designed to reflectively load an embedded PE payload directly in memory, supporting stealthy execution and defense evasion. Reported FIN7 use cases include deploying DiceLoader (also known as Lizar/IceBot), cracked Core Impact implants, Carbanak-related payload chains, NetSupport Manager RAT, Gracewire, and the Lizar post-exploitation tool. The malware has been used to support exploitation, lateral movement, persistence, and broader post-compromise activity.
Observed delivery and execution chains include malicious MSIX packages used in malvertising and SEO-poisoning campaigns impersonating legitimate software. In FIN7-related MSIX activity, the StartingScriptWrapper.ps1 component launched embedded PowerShell scripts that used process injection to execute POWERTRASH and Carbanak, which then delivered NetSupport Manager RAT. Microsoft also reported Sangria Tempest using malicious MSIX installations and Google-advertised lure pages that led to POWERTRASH, which then loaded NetSupport and Gracewire. Separate Microsoft reporting states FIN7 used the PowerShell-based POWERTRASH in-memory dropper in April 2023 intrusions to deploy the Lizar post-exploitation tool on compromised devices, after which the actor moved laterally and deployed Clop ransomware using OpenSSH and Impacket.
POWERTRASH is consistently associated in the provided content with FIN7 operations targeting multiple sectors, including hospitality, retail, finance, manufacturing, legal, public sector, and other opportunistically affected organizations. Known related infrastructure and indicators directly mentioned in the content include staging URLs hxxp://193.178.210[.]227/work_53.bin_m7.ps1 and hxxp://45.87.154[.]208/icsnd3b_64refl.ps1, which were reported to deliver POWERTRASH loaders for Core Impact and DiceLoader respectively.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Powertrash, a heavily obfuscated PowerShell script, is designed to reflectively load an embedded PE file in-memory, enabling the group to stealthily execute their backdoor payloads in their malicious campaigns.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Observed exploitation activities involve PowerShell droppers with multiple layers of obfuscation... In one specific intrusion, the group installed persistence on the exploited system using the SSH-based backdoor through a batch script named install.bat.
The packer employs anti-analysis techniques... The final PE payload is unpacked with two iterations of XOR decryption, separated by a step of LZNT1 decompression.
When victims open these MSIX packages, the StartingScriptWrapper.ps1 component launches embedded PowerShell scripts that employ process injection to execute POWERTRASH and Carbanak malware...
Powertrash, a heavily obfuscated PowerShell script, is designed to reflectively load an embedded PE file in-memory... The payload is not designed to be dropped directly on the disk and is compiled with the ReflectiveLoader implementation to allow in-memory reflective loading.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware executed via malicious MSIX packages using embedded PowerShell and process injection; used to help deliver NetSupport Manager RAT.
An obfuscated in-memory PowerShell loader used by FIN7 to deploy additional payloads and support exploitation, lateral movement, and persistence.
A heavily obfuscated PowerShell in-memory loader used by FIN7 to stealthily execute payloads such as backdoors and Core Impact implants while evading defenses.
Malware executed via process injection from a PowerShell script within a malicious MSIX chain; used to facilitate delivery of follow-on payloads (NetSupport Manager RAT).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.