Powercat is a PowerShell-based networking utility that is frequently used as a semi-legitimate post-exploitation tool and is also referenced as part of malware-enabled intrusion activity. It is commonly used to establish reverse or bind shells, execute commands remotely, and support lateral movement and internal reconnaissance on Windows systems. In intrusion reporting, Powercat has appeared both as a standalone offensive utility leveraged by threat actors and as a capability invoked by remote access malware to provide shell access on compromised hosts.
Powercat has been associated with multiple threat contexts. It has been used by Sofacy-linked operations alongside other administrative and reconnaissance tools for resource mapping and lateral movement. It has also been incorporated into a remote access trojan associated with Greenbug, where it was used to connect back to an operator-controlled server and provide interactive shell access. More recently, activity tracked under the name Powercat has been linked to a cybercriminal campaign targeting Roblox users through fake Xeno Executor installers distributed in gaming forums and Discord communities. In that campaign, victims were lured with purportedly undetected cheat tooling, leading to a multi-stage Java infection chain that deployed a Java-based remote access trojan and information stealer with expanded surveillance and remote administration features.
In the Roblox-focused campaign, the malware attributed to the Powercat cluster used staged loaders, anti-analysis checks, persistence, self-update functionality, browser and application data theft, cryptocurrency wallet targeting, keylogging, screenshot capture, webcam access, desktop streaming, file transfer, PowerShell execution, and interactive shell control. The campaign particularly targeted consumer Windows systems used by gamers, with elevated risk to younger users seeking third-party Roblox tooling. Across contexts, Powercat is best characterized as a tool or malware-associated shell-access component used for post-exploitation, remote command execution, reconnaissance, and lateral movement rather than a single consistently defined malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
It then launches an obfuscated Java payload disguised as ‘decompiler.exe,’ which performs environment checks, registers the victim, and downloads the final malware payload.
It then launches an obfuscated Java payload disguised as ‘decompiler.exe,’ which performs environment checks, registers the victim, and downloads the final malware payload.
To make these packages look authentic, the attackers recreate the directory structure of a legitimate Xeno installation, include some genuine Lua scripts, and use plausible filenames.
The malware looks for traces of debugging, artifacts that indicate sandbox execution... Sandbox detection is performed through several checks. The malware verifies whether the disk partition size exceeds 20 GB, looks for well-known MAC addresses associated with emulated network adapters, checks the registry and WMI for virtual machine artifacts, and iterates over running processes to detect monitoring tools.
The payload checks for a Java Runtime Environment, and extracts one if necessary... It then launches an obfuscated Java payload disguised as ‘decompiler.exe,’ which performs environment checks
Provides surveillance capabilities, including keylogging, mouse activity logging, screenshot capturing, desktop streaming, and webcam access.
Steals browser data including cookies and other stored user data from Chrome, Edge, Brave, Opera, and Vivaldi.
it starts collecting information about the environment in which it is running... The malware then contacts two online services that can identify IP addresses... to obtain geolocation information about the victim.
File system commands include standard directory listing, upload, download, and rename operations.
The malware looks for traces of debugging, artifacts that indicate sandbox execution... Sandbox detection is performed through several checks. The malware verifies whether the disk partition size exceeds 20 GB, looks for well-known MAC addresses associated with emulated network adapters, checks the registry and WMI for virtual machine artifacts, and iterates over running processes to detect monitoring tools.
The payload checks for a Java Runtime Environment, and extracts one if necessary... It then launches an obfuscated Java payload disguised as ‘decompiler.exe,’ which performs environment checks
It can steal browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information.
Provides surveillance capabilities, including keylogging, mouse activity logging, screenshot capturing, desktop streaming, and webcam access.
Provides surveillance capabilities, including keylogging, mouse activity logging, screenshot capturing, desktop streaming, and webcam access.
The payload checks for a Java Runtime Environment, and extracts one if necessary, then reads a local file containing the validation keys for the attackers' command-and-control (C2) server.
opens a connection to hxxps://solthere[.]net/justacoolkat10, and sends the JSON object through a POST request... The URL used for payload retrieval is hxxps://solthere[.]net/api/v1/redeem.
It then launches an obfuscated Java payload disguised as ‘decompiler.exe,’ which performs environment checks, registers the victim, and downloads the final malware payload.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Java-based malware family delivered via fake Xeno Executor installers targeting Roblox players. It uses a staged infection chain with an initial loader that checks for Java, launches an obfuscated Java payload, registers the victim with C2, and downloads a final payload that steals credentials, browser data, tokens, payment information, and cryptocurrency wallet data while also providing surveillance and full remote administration capabilities.
A multi-stage Java malware family disguised as a fake Xeno Roblox cheat. Its final stage functions as both an information stealer and remote access trojan, stealing browser cookies, Discord/Roblox/Minecraft accounts, crypto-wallet and payment data, while also supporting keylogging, webcam capture, desktop streaming, file manipulation, PowerShell command execution, persistence, self-update, and interactive remote control.
PowerShell-based networking utility (netcat-like) used for connectivity and remote command/channel establishment; referenced as a downloaded tool in xHunt operations.
PowerShell-based netcat-like utility used for connectivity, pivoting, and lateral movement in compromised environments (mentioned as used in Sofacy operations).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.