Core Impact is a commercial penetration testing and exploitation framework. In the provided content, it is referenced as an offensive tool used by FIN7, which delivered Core Impact loaders through its Powertrash PowerShell loader. SentinelOne linked this activity to underground purchases of cracked Core Impact copies by the FIN7-associated persona lefroggy, and separate reporting noted listings for cracked Core Impact 21.3 on the RAMP cybercrime forum. The content also states that FIN7’s arsenal included Core Impact alongside Powertrash, Diceloader, an SSH-based backdoor, and AvNeutralizer. FIN7 has targeted sectors including hospitality, energy, finance, high-tech, retail, and in observed 2022 activity also U.S. manufacturing, legal, and public-sector organizations. High-confidence infrastructure associated with FIN7 delivery of Powertrash loaders included hxxp://193.178.210[.]227/work_53.bin_m7.ps1, which delivered a Powertrash loader for Core Impact. The content does not describe Core Impact itself as malware, but as a legitimate pentesting suite that was used operationally by a threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Core Impact is a penetration testing tool designed for exploitation activities... FIN7 has been delivering Core Impact loaders through Powertrash in their campaigns.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The PowerShell droppers employed in these campaigns deliver Powertrash loaders from staging servers... These Powertrash loaders allow the group to gain control over compromised victim systems by loading a backdoor payload.
Cracked versions of commercial penetration testing tools like Cobalt Strike ($5,900/year) and Core Impact ($20,000+/year) further lower barriers. These tools, designed for legitimate security testing, provide professional-grade attack capabilities at zero cost to criminals.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A commercial penetration testing tool referenced as a cracked offering on RAMP for criminal use.
A legitimate penetration testing framework abused by FIN7 for exploitation and deployment of PIC implants with encrypted C2 communications.
Legitimate penetration testing framework mentioned as an offensive tool associated with a potentially related online persona; no direct deployment details provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.