PowerNet is a custom PowerShell loader associated with the GrayAlpha threat cluster, which overlaps with FIN7. According to the provided reporting, PowerNet decompresses and executes NetSupport RAT and has been used as part of GrayAlpha infection chains. High-confidence reporting states that GrayAlpha used three primary delivery vectors that ultimately led to NetSupport RAT infections: fake browser update pages, fake 7-Zip download sites, and the TAG-124 traffic distribution system; specifically, PowerNet was used in the fake 7-Zip and TAG-124 infection paths, while the fake browser update path used the separate MaskBat loader. The activity is tied to financially motivated operations linked to the broader FIN7 ecosystem. The content does not provide specific file hashes, domains, or other direct IOCs uniquely attributable to PowerNet itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Insikt Group discovered a custom PowerShell loader named PowerNet, which decompresses and executes NetSupport RAT.
Insikt Group discovered a custom PowerShell loader named PowerNet, which decompresses and executes NetSupport RAT.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom PowerShell loader used to decompress and execute NetSupport RAT.
Custom PowerShell-based loader used in the fake 7-Zip and TAG-124 distribution vectors to decompress and execute NetSupport RAT.
A custom PowerShell loader used by GrayAlpha that decompresses and executes NetSupport RAT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.