CharmPower is a modular PowerShell backdoor associated with the Iranian threat actor APT35, also tracked as Phosphorus, Charming Kitten, and overlapping with Microsoft’s Mint Sandstorm reporting. It has been observed in targeted intrusion activity against high-value organizations and individuals, including campaigns aimed at think tanks and universities, as well as in exploitation chains leveraging Log4Shell. Separate reporting also ties its delivery to phishing operations that used remote template injection.
The malware is designed for post-compromise control and host profiling. Documented behaviors include execution and command-and-control activity through PowerShell, retrieval of command-and-control domain information from actor-controlled cloud storage, and delivery of additional modules encoded with Base64. CharmPower performs reconnaissance by enumerating local network configuration with native utilities, querying WMI for host information, and inspecting installed software through Windows Registry Uninstall data. It can list installed applications and gather system details useful for follow-on operations.
CharmPower also supports data theft and operational cleanup. It can exfiltrate collected information to command-and-control infrastructure over HTTP POST, and reporting indicates it can also send victim data via FTP. Registry interaction includes enumeration of installed-software information and removal of persistence-related artifacts, indicating both discovery and defense-evasion or cleanup functions. Overall, CharmPower fits APT35’s broader pattern of PowerShell-centric, modular intrusion tooling used for espionage-oriented access, reconnaissance, and follow-on payload delivery on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In Mid-January, the Iran-linked APT35 group has been observed leveraging the Log4Shell flaw to drop a new PowerShell backdoor tracked as CharmPower.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In Mid-January, the Iran-linked APT35 group has been observed leveraging the Log4Shell flaw to drop a new PowerShell backdoor tracked as CharmPower.
CharmPower is a modular backdoor written in PowerShell that this subgroup delivers in phishing campaigns that rely on template injection.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
In Mid-January, the Iran-linked APT35 group has been observed leveraging the Log4Shell flaw to drop a new PowerShell backdoor tracked as CharmPower.
Microsoft has also observed this Mint Sandstorm subgroup using a distinct attack chain involving low-volume phishing campaigns and a third custom implant.
In an effort to further gain the target’s confidence, Charming Kitten continued the interaction with another benign email containing a list of questions... After multiple days of benign and seemingly legitimate interaction, Charming Kitten finally sent a “draft report”... a password-protected RAR file containing a malicious LNK file.
Level 2: Kills all malware related processes and then deletes the corresponding files; also deletes a scheduled task that was not created by any file observed by Volexity during this investigation
POWERSTAR can execute commands in two programming languages, PowerShell and CSharp... start PowerShell, CSharp Executes a code block in a new thread.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
This file has been weaponized with macros to perform remote template injection
Level 2: Kills all malware related processes and then deletes the corresponding files; also deletes a scheduled task that was not created by any file observed by Volexity during this investigation
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
High-level obfuscation and custom code: Designed to bypass security tools that rely on identifying known malware signatures or behaviors.
Their malware often tries to behave like legitimate web browser activities to evade Network Intrusion Detection Systems (NIDS).
Cleanup Modules... Level 3: Deletes all the persistence-related registry keys and corresponding files Level 4: Kills all processes whose executable resides in the directory %appdata%/Microsoft/Notepad , then deletes all files recursively in this directory
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Microsoft reports Mint Sandstorm distributing OneDrive-hosted PDF files containing URLs to download a DOTM from Dropbox. Once executed, template injection is abused to execute POWERSTAR which is hosted on OneDrive.
The decrypted code is then executed in memory within the same PowerShell instance. This is the primary POWERSTAR backdoor payload. The same general technique is repeated throughout the POWERSTAR framework, with additional modules downloaded and executed in memory.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
When successfully executed, the primary POWERSTAR backdoor payload collects a small amount of system information from the compromised machine and sends it via a POST request to the C2 address... screenshots taken by the malware can be exfiltrated via HTTP or FTP
The Drokbk backdoor issues a web request to obtain the contents of a README file on a Mint Sandstorm-controlled GitHub repo.
A malicious LNK file downloads the initial POWERSTAR script from a Backblaze B2 bucket... additional modules downloaded and executed in memory.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
41 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat Details and IOCs Malware: BASICSTAR, CharmPower, GORBLE, GorjolEcho, NICECURL, POWERSTAR, TAMECAT
... CharmPower ... (v1.0→v1.1) ...
CharmPower (v1.0→v1.1)
Previously observed TA453 malware referenced as part of the lineage preceding BlackSmith/AnvilEcho.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.