PowerStallion is a PowerShell-based backdoor associated with the Turla espionage group. It has been used as an existing access mechanism and staging implant in intrusions targeting high-value government and diplomatic organizations, and has been observed alongside other Turla tooling including ComRAT and an RPC backdoor. The malware is notable for abusing Microsoft OneDrive as a command-and-control channel, mapping the service as a network drive and then using PowerShell loops to repeatedly poll for operator commands. PowerStallion supports post-compromise monitoring functions including process-list collection, and it has been used to deploy additional payloads such as ComRAT. For defense evasion and anti-forensics, it modifies timestamps on local log files to blend with legitimate system artifacts. Its tradecraft reflects Turla’s preference for stealthy, PowerShell-centric operations and use of trusted third-party services to conceal command-and-control traffic on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The same provider was used for the Outlook backdoor and for an undocumented PowerShell backdoor we named PowerStallion.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The adversaries had communicated to both Dropbox and Pastebin. APT28 has used Google Drive for C2. APT37 leverages social networking sites and cloud platforms (AOL, Twitter, Yandex, Mediafire, pCloud, Dropbox, and Box) for C2.
"APT39 has communicated with C2 through files uploaded to and downloaded from DropBox."; "RIFLESPINE can retrieve C2 commands from an encrypted file on Google Drive then upload the results ... back to Google Drive."; "CloudDuke uses a Microsoft OneDrive account to exchange commands and stolen data"
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that alters MAC times of local log files to match benign system files.
Malware using PowerShell loops to poll OneDrive-based C2 for commands.
Malware that uses PowerShell loops to poll its OneDrive-based C2 for commands.
Backdoor malware used to monitor process lists.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.