POSHSPY is a stealth-focused Windows backdoor associated with APT29 and used since at least 2015 as a secondary or backup access mechanism in espionage operations. It is notable for a living-off-the-land design that relies heavily on native Windows components, especially PowerShell and Windows Management Instrumentation (WMI), to reduce forensic visibility and blend into legitimate administrative activity.
The malware establishes persistence through a WMI permanent event subscription. In documented deployments, encrypted and Base64-encoded PowerShell backdoor code was stored inside a custom WMI class property, while a WMI event filter and command-line event consumer were used to trigger execution on a schedule. When activated, the consumer launched a PowerShell command that extracted, decrypted, and executed the payload. This architecture allowed POSHSPY to function as a highly covert, file-light backdoor and to remain available if operators lost access to a primary implant.
POSHSPY uses PowerShell extensively for command execution and payload launch. For command and control resilience, it can derive command-and-control URLs through a domain generation algorithm based on a word list. Its communications have been reported as protected with AES and RSA encryption. For data theft, it uploads information in fixed-size chunks, and it also employs anti-forensic timestamp manipulation by modifying downloaded executables to match older legitimate files. These behaviors align with long-term clandestine collection and defense-evasion objectives typical of APT29 intrusions.
POSHSPY has been linked to Russian state-aligned cyberespionage activity attributed to APT29, also known as Cozy Bear or Midnight Blizzard. Its tradecraft is consistent with operations targeting organizations of intelligence value, particularly government, diplomatic, and other strategically significant entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
POSHSPY uses a DGA to derive command and control URLs from a word list.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
WMI Filter named “BfeOnServiceStartTypeChange” was created to execute the event every Monday, Tuesday, Thursday, Friday and Saturday at 11:33 am Local time
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
APT29 used Cobalt Strike, Silver Red teaming framework, and Zulip for C&C, aligning with their pattern of using legitimate services like Dropbox and OneDrive.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Examples include: "encrypts some C2 with RSA", "RSA encryption for C2 communications", "hard-coded RSA public key", "RSA-2048", "RSA-4096", and "REvil has encrypted C2 communications with the ECIES algorithm". | Examples include: "encrypt C2 messages with AES-256-CBC sent underneath TLS", "encrypts C2 traffic with AES and RSA", "uses SSL/TLS and RC4", and "BlowFish algorithm".
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy PowerShell backdoor that uses WMI permanent event subscriptions for covert persistence. It stores encrypted, base64-encoded PowerShell payloads in a custom WMI class and executes them via a CommandLineEventConsumer on a scheduled trigger.
A stealthy backdoor that uses WMI for storage and persistence and executes PowerShell payloads while blending with legitimate traffic.
Malware that modifies timestamps of downloaded executables to match older files for stealth.
PowerShell-based malware used to execute commands and payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.