POWERSOURCE is a PowerShell backdoor associated with targeted intrusion activity linked by multiple vendors to FIN7, with some historical overlap and confusion involving DNSMessenger-related activity and later reporting that similar infrastructure also appeared in MuddyWater operations. It is described as a heavily obfuscated and modified derivative of the public DNS_TXT_Pwnage tool and is designed to operate largely in memory while using DNS TXT records as a covert command-and-control channel.
POWERSOURCE is typically delivered through malicious Microsoft Office documents in spearphishing campaigns. Reported infection chains include documents that abuse Dynamic Data Exchange to execute PowerShell without relying on macros, as well as documents that drop a VBS script which installs the backdoor. After execution, POWERSOURCE decodes and launches PowerShell payloads, can store components in the Windows Registry, and on systems with newer PowerShell versions can hide a decoded payload in an NTFS alternate data stream for defense evasion.
The malware establishes persistence through Registry Run keys and has also been reported in broader DNSMessenger-style chains that use scheduled tasks and WMI event subscriptions depending on privilege level and host configuration. POWERSOURCE queries Registry locations as part of preparing persistence. Its command-and-control traffic uses DNS TXT queries and responses to exchange attacker tasking and results, allowing remote execution while blending into commonly permitted DNS traffic.
POWERSOURCE has been used to deliver additional payloads, notably the memory-resident PowerShell backdoor TEXTMATE, which provides an interactive reverse shell over DNS, and in some cases Cobalt Strike Beacon. Observed targeting linked to POWERSOURCE activity included U.S.-based organizations in financial services, transportation, retail, education, IT services, and electronics. The malware is best characterized as a PowerShell-based backdoor used for covert post-compromise access, persistence, and staged delivery of follow-on tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Powersource — Version modifiée de l’outil public DNS_TXT_Pwnage. | Textmate — Distribué par Powersource. S’exécute en mémoire via Powershell.
Palo Alto Networks believe that the recent wave of attacks might have been mistakenly associated with the FIN7 group, it also reported that a C&C server delivering the FIN7-linked DNSMessenger tool was in MuddyWater attacks as well.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Le vecteur d’infection principalement employé par FIN7 est le courriel d’hameçonnage. Il contient une pièce jointe malveillante et plus rarement une URL pointant vers des sites compromis ou des services légitimes tels que Google Docs.
The eSentire Security Operations Center has observed a spear phishing campaign targeting customers in the financial industry. The email claims to originate from the Securities and Exchange Commission and arrives bundled with a malicious Microsoft Word Document.
The command is then executed using the Windows Management Interface (WMI) Win32_Process object using the Create method.
the malware also creates a Scheduled Task on the infected system named "kernel32"
Using this channel, the attackers were able to directly interact with the Windows Command Processor using the contents of DNS TXT record queries and the associated responses generated on the attacker-controlled DNS server.
The document uses the Dynamic Data Exchange (DDE) protocol to execute malicious PowerShell code which downloads and executes DNSMessenger malware.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The document uses the Document_Open() function to call another VBA function.
the malware also creates a Scheduled Task on the infected system named "kernel32"
If the system is running an earlier version of Powershell, the Stage 3 payload is encoded and written to the registry location dictated by the assignment of $reg_win_path earlier with the key name of 'kernel32'.
If the user has administrative privileges on the infected system, it will set up a WMI event consumer and filter as an additional WMI-based persistence mechanism. The filter name is "kernel32_filter" and the consumer name is "kernel32_consumer".
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
the malware also creates a Scheduled Task on the infected system named "kernel32"
If the user has administrative privileges on the infected system, it will set up a WMI event consumer and filter as an additional WMI-based persistence mechanism. The filter name is "kernel32_filter" and the consumer name is "kernel32_consumer".
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The code in Stage 2 has been obfuscated... Base64 string encoding was also present throughout the script.
A second block of code present in the Powershell is called $stagerCode and is responsible for extracting and decoding the code that was previously stored in the registry, then executing this code, first checking for the presence of the mutex '1823821749'. If this mutex does not exist, execution continues.
The malware then queries the system to determine the characteristics of the environment in which it is operating... It specifically checks the version of Powershell that is installed on the system... The malware also obtains the serial number of the system from the BIOS.
Once installed, DNSMessenger malware uses DNS TXT queries to create a bidirectional command and control (C2) channel between the victim and the attacker.
136 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor implemented in PowerShell.
Remote access trojan that uses DNS-related tradecraft and executes malicious PowerShell commands on compromised systems.
Malware that persists by setting a Registry Run key with path selection based on privilege level.
Backdoor implemented in PowerShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.