FIREPOWER is a PowerShell-based backdoor observed by Zscaler ThreatLabz in the active “Sheet Attack” campaign targeting primarily Windows systems in India, including Indian government entities (campaign attributed with medium confidence to a Pakistan-linked actor, possibly a new subgroup or an APT36 faction). Recent activity used malicious LNK files that launch headless PowerShell with a Base64-encoded command to retrieve and execute a remote script from attacker infrastructure (e.g., using PowerShell irm to fetch from domains such as hcidoc[.]in and piping to iex). For command-and-control, FIREPOWER connects to a Firebase Realtime Database and creates per-victim keys/fields including status, eStatus, comStatus, extension, url, command, and LastHit to manage victim state and tasking. It performs host reconnaissance by enumerating directories under C:\Program Files and C:\Program Files (x86) and collecting file/directory names from the Desktop and Downloads folders, uploading these lists to Firebase. FIREPOWER runs a C2 loop with a 300-second polling interval, uses a hardcoded Windows 10 x64 User-Agent for downloads, and executes received commands via Invoke-Expression; at least some variants append command results to C:\Users\Public\Documents\text.log. ThreatLabz also observed FIREPOWER being used to deliver second-stage tooling, including a PowerShell document stealer that searches Desktop, Documents, and OneDrive for specific file extensions and exfiltrates stolen files to a threat actor-controlled private GitHub repository.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Secondary toolset in the 'Sheet Attack' campaign used post-compromise (noted for credential harvesting, lateral movement, and persistence).
Secondary tool in the Sheet Attack campaign used post-compromise (described for credential harvesting, lateral movement, and persistence).
PowerShell backdoor delivered via malicious LNK that runs a base64-encoded PowerShell stager to fetch the script from attacker infrastructure. Uses Firebase Realtime Database for C2 with per-victim keys/flags to download files from attacker-specified URLs and execute commands via Invoke-Expression; collects directory listings (Desktop/Downloads/Program Files) and uploads them to Firebase; maintains a polling loop (commonly 300s, variants 120s). Variants add persistence via scheduled task, store last command output in Firebase, embed lure PDFs, delete original LNK, and reduce on-disk artifacts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.