PowerTrick is a PowerShell-based framework associated with the TrickBot crimeware ecosystem and the Anchor intrusion set. It has been used by TrickBot operators during post-compromise operations to support enterprise network exploration, pivoting, and follow-on payload deployment. Reporting links it to the broader WIZARD SPIDER cluster and places it alongside other related tooling such as TrickBot, BazaLoader, BazaBackdoor, and Anchor.
PowerTrick has been observed in intrusions after initial TrickBot access was already established, where operators used it together with Cobalt Strike and other offensive tooling to profile victim environments, enumerate domain infrastructure, identify privileged accounts, scan for additional hosts, and move laterally across Windows networks. These operations have included credential dumping, domain reconnaissance, host profiling, and preparation for deployment of higher-impact payloads. In documented cases, PowerTrick-supported activity formed part of attack chains that culminated in deployment of the Anchor backdoor and Ryuk ransomware.
Victimology indicates use against corporate environments rather than consumer systems, with emphasis on compromised enterprise domains that could be monetized through ransomware. PowerTrick has also been discussed in connection with environments later involved in payment-card web skimming investigations, although the strongest high-confidence characterization is its role as a post-exploitation framework used by TrickBot and Anchor operators for internal reconnaissance, lateral movement, and staging of subsequent malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerTrick is described as a custom PowerShell framework used by TrickBot operators in post-compromise activity against high-profile victims.
PowerTrick is named as one of the TrickBot gang's malicious tools used to access corporate networks, steal files and credentials, and facilitate ransomware deployment.
Malware family referenced as having code similarities to TrickBot.
PowerTrick is a PowerShell-based framework used by TrickBot/Anchor actors for pivoting and operating within compromised networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.