POWBAT is a backdoor malware family/variant observed in Iranian-linked cyber-espionage activity. Reporting cited in the content describes POWBAT infections commonly resulting from spearphishing emails containing malicious attachments and/or hyperlinks. A separate spearphishing campaign targeting banks in the Middle East used macro-enabled attachments to distribute POWBAT.
POWBAT is associated in the content with multiple Iranian intrusion sets:
The content does not provide specific technical details of POWBAT’s internal functionality (e.g., command set, persistence mechanisms, C2 protocols) beyond identifying it as a backdoor used to establish a foothold, nor does it provide POWBAT-specific indicators of compromise (hashes/domains) in the provided excerpts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...spear phishing emails with malicious attachments and/or hyperlinks typically resulting in a POWBAT infection... APT39 leverages custom backdoors such as SEAWEED, CACHEMONEY, and a unique variant of POWBAT...
...spear phishing emails with malicious attachments and/or hyperlinks typically resulting in a POWBAT infection... APT39 leverages custom backdoors such as SEAWEED, CACHEMONEY, and a unique variant of POWBAT...
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor (variant referenced) used by APT39/Chafer to support stealthy access in espionage campaigns.
Malware distributed via macro-enabled spearphishing attachments in a campaign targeting Middle East banks (attributed here to APT34).
Referenced as an infection outcome from APT39 spearphishing; no additional functional details are provided in this content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.