PowerModul is a PowerShell implant associated with the GOFFEE threat actor, also known as Paper Werewolf, and observed in targeted intrusions against organizations in the Russian Federation during 2024. It functions primarily as a downloader and execution component within GOFFEE’s intrusion chain, retrieving additional PowerShell payloads from command-and-control infrastructure and executing them on compromised hosts. Reported victims included organizations in media, telecommunications, construction, government, and energy sectors.
PowerModul was delivered through spearphishing campaigns using malicious archive attachments. Observed infection chains included archives containing either a disguised executable masquerading as a document or a malicious Microsoft Office document with VBA macros. In the macro-based chain, user interaction to enable content triggered creation of HTA, JavaScript, and PowerShell stages that ultimately launched the PowerModul payload and established persistence for the current user.
The implant communicates with its command-and-control server using its own protocol and receives XML-formatted responses containing encoded scripts for execution. It can identify the infected system to the operator and includes functionality to decode and run embedded content offline. PowerModul has been used to deliver additional GOFFEE tooling, including the PowerTaskel Mythic agent, a removable-media file theft component known as FlashFileGrabber, and a USB-propagation component referred to as USB Worm. Through these follow-on payloads, the broader toolchain supports data theft from removable media, exfiltration, and propagation via USB devices.
PowerModul is distinct from PowerTaskel despite operational overlap, and its use reflects GOFFEE’s evolution toward modular Mythic-based tradecraft. In the same campaigns, GOFFEE also used administrative utilities and remote execution mechanisms such as PsExec, mshta.exe, WinRM, HTA/JScript chains, and shellcode-loading techniques for privilege escalation, lateral movement, and post-exploitation. PowerModul is best characterized as a modular PowerShell downloader used as an entry point for additional payload delivery within GOFFEE operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
USB Worm is capable of infecting removable media with a copy of PowerModul... The worm renames the files on the removable disk... copies PowerModul... creates hidden VBS and batch files... A shortcut is also created with the original name of the decoy document.
The starting point is typically a phishing email with a malicious attachment... The first infection scheme uses a RAR archive with an executable file masquerading as a document... In the second case, the RAR archive contains a Microsoft Office document with a macro that serves as a dropper.
Злоумышленники всё реже используют "классические" вредоносные программы и опираются на легитимные утилиты удалённого управления, PowerShell-скрипты (T1059.001) и облачные сервисы.
it first uses cmd.exe and output redirection to drop a JavaScript file named “UserCacheHelper.lnk.js” onto the disk...
The RAR archive contains a Microsoft Office document with a macro that serves as a dropper... Clicking “Enable Content” activates a macro...
the macro creates two files... and writes the HTA into the registry using the “LOAD” registry value of the “HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows” registry key... the programs listed in the “LOAD” value of the registry key are run automatically for the currently logged-on user.
the macro creates two files... and writes the HTA into the registry using the “LOAD” registry value of the “HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows” registry key... the programs listed in the “LOAD” value of the registry key are run automatically for the currently logged-on user.
The shellcode... contains an obfuscated Mythic agent... the PowerModul code is embedded in the “UserCache.ini” file as a Base64-encoded string... request payloads are... encoded using XOR... and then converted to Base64.
USB Worm is capable of infecting removable media with a copy of PowerModul... The worm renames the files on the removable disk... copies PowerModul... creates hidden VBS and batch files... A shortcut is also created with the original name of the decoy document.
When accessing the C2, PowerModul appends an infected system identifier string to the C2 URL... The response from the C2 is in XML format...
PowerModul is a PowerShell script capable of receiving and executing additional PowerShell scripts from the C2 server... Initially, it was used to download and launch the PowerTaskel implant... user.txt is another PowerShell script whose task is to extract a payload from a hardcoded address and execute it.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom agent/backdoor associated with GOFFEE operations using the Mythic framework.
Implant used in targeted attacks against Russian entities across multiple sectors (July-Dec 2024).
Implant referenced in the GOFFEE campaign (H2 2024) alongside a shift to a binary Mythic agent; specific capabilities are not detailed in the provided content.
PowerShell-имплант, способный получать с командного сервера дополнительные PowerShell-скрипты и выполнять их. Использовался как загрузчик для PowerTaskel, FlashFileGrabber и USB Worm; имеет функцию OfflineWorker для выполнения встроенной полезной нагрузки.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.