PowerRun is a legitimate Windows utility that launches applications, executables, and scripts with elevated privileges, including SYSTEM-level execution. Although not malware in itself, it is frequently abused by threat actors as a post-compromise privilege-enablement tool to run other utilities with high integrity, bypass user-mode protections, and facilitate defense evasion. Observed malicious use includes executing tools intended to disable or terminate security products and other protected services.
PowerRun has appeared in ransomware intrusion chains as an auxiliary utility rather than a primary payload. It has been used by operators associated with The Gentlemen ransomware activity and in Trigona-linked intrusions, where it supported elevated execution of security-disabling tools and other attacker utilities. In these operations, PowerRun formed part of a broader toolkit that also included remote-access software, credential theft tools, vulnerable-driver abuse, and custom or commodity ransomware components.
The utility runs on Windows systems and is typically introduced after initial compromise, when attackers already possess some level of access and seek stronger execution context for follow-on actions. Its role is best characterized as post-exploitation support for privilege escalation and defense evasion rather than standalone malware functionality.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Next, they deployed PowerRun.exe, a legitimate tool frequently abused for privilege escalation. By leveraging PowerRun.exe, the attackers attempted to execute high-privilege operations, aiming to disable or terminate security-related services and processes.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate but frequently abused utility used here to execute high-privilege operations in support of defense evasion, particularly to disable or terminate security-related services and processes.
A utility used to execute attacker tools with elevated privileges during the Trigona attack chain.
A utility used to run attacker tools with elevated system privileges, enabling administrative-level execution during the campaign.
PowerRun is a utility used to launch applications, executables, and scripts with elevated privileges, helping attackers bypass user-mode protections during Trigona intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.