POWERSOURCE is a PowerShell-based backdoor associated with FIN7-linked intrusion activity and also discussed alongside DNSMessenger and TEXTMATE. It is a heavily obfuscated and modified derivative of the public DNS_TXT_Pwnage tool and is designed to operate largely in memory while using DNS TXT records as a covert command-and-control channel. Campaigns involving POWERSOURCE used malicious Office documents and VBS-based staging to install the backdoor, and related activity also included spearphishing lures themed as regulatory or business communications.
On compromised Windows systems, POWERSOURCE executes through PowerShell and can store decoded payload material in alternate data streams or in the Windows Registry, depending on the PowerShell version and execution context. It has been observed achieving persistence through Registry Run keys, and related reporting also describes use of scheduled tasks and WMI event subscriptions in closely related DNS-based PowerShell intrusion chains. POWERSOURCE queries Registry locations as part of preparing persistence and environment handling.
Its core functionality is to establish a covert backdoor over DNS, allowing attackers to deliver additional PowerShell payloads and maintain remote access while blending with routine name-resolution traffic. POWERSOURCE has been used to deliver the second-stage PowerShell backdoor TEXTMATE, which provides an interactive reverse shell, and in some cases has also delivered Cobalt Strike Beacon. The malware has been linked to targeted operations against U.S.-based organizations in sectors including financial services, retail, transportation, education, information technology services, and electronics. The tooling overlap with DNSMessenger and other FIN7 tradecraft has made attribution complex in some reporting, but POWERSOURCE is consistently characterized as a PowerShell backdoor used in targeted post-compromise operations on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Powersource — Version modifiée de l’outil public DNS_TXT_Pwnage. | Textmate — Distribué par Powersource. S’exécute en mémoire via Powershell.
Palo Alto Networks believe that the recent wave of attacks might have been mistakenly associated with the FIN7 group, it also reported that a C&C server delivering the FIN7-linked DNSMessenger tool was in MuddyWater attacks as well.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Le vecteur d’infection principalement employé par FIN7 est le courriel d’hameçonnage. Il contient une pièce jointe malveillante et plus rarement une URL pointant vers des sites compromis ou des services légitimes tels que Google Docs.
Le vecteur d’infection principalement employé par FIN7 est le courriel d’hameçonnage. Il contient une pièce jointe malveillante.
The command is then executed using the Windows Management Interface (WMI) Win32_Process object using the Create method.
the malware also creates a Scheduled Task on the infected system named "kernel32"
Using this channel, the attackers were able to directly interact with the Windows Command Processor using the contents of DNS TXT record queries and the associated responses generated on the attacker-controlled DNS server.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The document uses the Document_Open() function to call another VBA function.
the malware also creates a Scheduled Task on the infected system named "kernel32"
If the system is running an earlier version of Powershell, the Stage 3 payload is encoded and written to the registry location dictated by the assignment of $reg_win_path earlier with the key name of 'kernel32'.
If the user has administrative privileges on the infected system, it will set up a WMI event consumer and filter as an additional WMI-based persistence mechanism. The filter name is "kernel32_filter" and the consumer name is "kernel32_consumer".
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
the malware also creates a Scheduled Task on the infected system named "kernel32"
If the user has administrative privileges on the infected system, it will set up a WMI event consumer and filter as an additional WMI-based persistence mechanism. The filter name is "kernel32_filter" and the consumer name is "kernel32_consumer".
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The code in Stage 2 has been obfuscated... Base64 string encoding was also present throughout the script.
A second block of code present in the Powershell is called $stagerCode and is responsible for extracting and decoding the code that was previously stored in the registry, then executing this code, first checking for the presence of the mutex '1823821749'. If this mutex does not exist, execution continues.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The malware then queries the system to determine the characteristics of the environment in which it is operating... It specifically checks the version of Powershell that is installed on the system... The malware also obtains the serial number of the system from the BIOS.
leveraged an interesting infection process using DNS TXT records to create a bidirectional command and control (C2) channel... The same generated hostname is then used by the malware to make a TXT record request.
This allows the attacker to send commands to be executed directly by the Command Processor and receive the output of those commands all using DNS TXT requests and responses.
135 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor implemented in PowerShell.
Remote access trojan that uses DNS-related tradecraft and executes malicious PowerShell commands on compromised systems.
Malware that persists by setting a Registry Run key with path selection based on privilege level.
Backdoor implemented in PowerShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.