Frankenstein is a Windows malware family that uses PowerShell-heavy staging and post-compromise activity to deliver additional payloads, perform host reconnaissance, evade analysis, maintain persistence, and communicate with command-and-control infrastructure. It has been delivered through trojanized Microsoft Word documents sent by email that rely on users enabling macros, after which malicious scripts execute base64-encoded PowerShell commands. These commands function as a stager, deobfuscate embedded content, and retrieve follow-on payloads.
Frankenstein conducts host enumeration that includes collecting the current username, machine name, administrative privilege context, public IP address, and lists of running processes. It also uses WMI queries to detect virtualization environments and analysis tools, indicating anti-analysis and defense-evasion behavior. Persistence is established through a scheduled task masquerading as a legitimate update mechanism. Communications with command-and-control infrastructure have used encrypted channels employing RC4 and AES-CBC. Frankenstein has also leveraged Empire to collect information and automatically return it to operator-controlled infrastructure.
The observed tradecraft is consistent with a staged intrusion toolset oriented toward reconnaissance, payload retrieval, persistence, and covert post-exploitation on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Examples throughout the content include: "APT29 used named and hijacked scheduled tasks to establish persistence"; "APT3 downloader creates persistence by creating the following scheduled task: schtasks /create ... /sc ONLOGON"; "Shamoon ... scheduling an unnamed task to execute the malware"; "menuPass ... execute a command on a target machine via Task Scheduler."
The content repeatedly describes threat actors and malware using PowerShell commands/scripts to download, execute, load in memory, and run payloads, e.g., "APT28 downloads and executes PowerShell scripts" and "APT3 has used PowerShell on victim systems to download and run payloads after exploitation."
"...leveraged the Chrome vulnerability, CVE-2022-0609, in combination with a Drive-by Compromise website." / "...has exploited client software vulnerabilities for execution..." / "...has used multiple software exploits for common client software...to gain code execution."
Examples throughout the content include: "APT29 used named and hijacked scheduled tasks to establish persistence"; "APT3 downloader creates persistence by creating the following scheduled task: schtasks /create ... /sc ONLOGON"; "Shamoon ... scheduling an unnamed task to execute the malware"; "menuPass ... execute a command on a target machine via Task Scheduler."
Examples throughout the content include: "APT29 used named and hijacked scheduled tasks to establish persistence"; "APT3 downloader creates persistence by creating the following scheduled task: schtasks /create ... /sc ONLOGON"; "Shamoon ... scheduling an unnamed task to execute the malware"; "menuPass ... execute a command on a target machine via Task Scheduler."
"Frankenstein has used PowerShell to run a series of base64-encoded commands, that acted as a stager and enumerated hosts."
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that deobfuscates Base64-encoded commands to retrieve additional payloads.
Malware using PowerShell stagers and host enumeration commands.
Malware/stager using base64-encoded PowerShell commands for staging and host enumeration.
Backdoor that performs process discovery across hosts for reconnaissance.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.