PowMix is a previously unreported PowerShell-based botnet/backdoor identified by Cisco Talos in a campaign active since at least December 2025 and targeting the workforce in the Czech Republic. Reported targeting included HR, legal, recruitment, and job-seeking victims, with lures themed around compliance, compensation data, Czech legislative references, and impersonation of the EDEKA brand. The infection chain likely begins with phishing emails delivering a malicious ZIP archive containing a Windows LNK file. Execution of the LNK launches a PowerShell loader that copies the archive into ProgramData, bypasses AMSI by setting AmsiUtils.amsiInitFailed via reflection, extracts a hidden encoded command from the ZIP data blob using a hardcoded marker, reconstructs a secondary PowerShell payload, and executes PowMix directly in memory.
PowMix is designed for remote access, reconnaissance, persistence, and remote code execution. It hides its PowerShell console via ShowWindowAsync, validates execution context tied to the shortcut path in ProgramData, queries the Windows ProductID from HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion, and uses a CRC32-style checksum over host/configuration data to derive a unique bot ID and a scheduled task name. Persistence is established through a Windows scheduled task with a random-looking hexadecimal name, observed configured to run daily at 11:00 a.m. and launch Windows Explorer with the malicious shortcut as an argument. It also creates a mutex in the form Global[BotID] to prevent multiple instances.
For command and control, PowMix uses randomized beaconing intervals rather than persistent connections, with observed jitter ranges of 0-261 seconds initially and 1,075-1,450 seconds later. It constructs C2 URLs using the base domain, bot ID, configuration hash, encrypted heartbeat data, a hexadecimal Unix timestamp, and a random hexadecimal suffix, embedding encrypted heartbeat data and victim identifiers into URL paths to resemble legitimate REST API traffic. It uses a Chrome user agent, sets Accept-Language and Accept-Encoding headers, and adopts system proxy settings with GetSystemWebProxy and DefaultCredentials. PowMix decrypts its C2 domain and local configuration with a custom XOR-based routine and can migrate C2 by writing a new encrypted domain into its configuration file. Reported commands include #KILL for self-deletion, #HOST for C2 migration, and non-prefixed responses for arbitrary code execution via dynamically reconstructed Invoke-Expression.
Talos reported tactical overlaps between PowMix and the earlier ZipLine campaign, including ZIP-based payload delivery, scheduled-task persistence, and use of Heroku for command-and-control infrastructure. The final operational objective of the campaign was not determined in the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
With its usage of ZIP-based payload distribution, scheduled task persistence, and Heroku exploitation for C2...
With its usage of ZIP-based payload distribution, scheduled task persistence, and Heroku exploitation for C2...
...deploys a PowerShell loader that extracts, decrypts, and executes the PowMix botnet in memory
The script parses the malicious ZIP file to locate a specific marker that is hardcoded, such as zAswKoK. This marker is treated as a delimiter, enabling the extraction of a hidden, encoded command that is embedded within the ZIP file data blob.
#KILL - The KILL command initiates a self-deletion routine, utilizing the Unregister-ScheduledTask PowerShell command with the parameter Confirm: $false to silently remove persistence, followed by Remove-Item -Recurse–Force command to wipe the malware’s directory in the victim machine.
PowMix also facilitates the remote execution of commands for self-deletion and C2 migration
...a PowerShell loader that extracts, decrypts, and executes the PowMix botnet in memory
The mutex implementation in the botnet prevents multiple instances from running at the same time. It creates a mutex with the name “Global\[BotID]”.
Before attempting to establish persistence, PowMix performs several validation checks to ensure that another instance of the botnet is not running in the infected machine. It examines the process tree using Common Information Model (CIM) queries to identify its parent processes.
It retrieves the machine's product ID by querying the HKLM: SOFTWARE\Microsoft\Windows NT\CurrentVersion registry key for the Windows ProductID.
It utilizes the GetSystemWebProxy API along with DefaultCredentials to dynamically adopt the host machine’s network proxy settings and automatically authenticates using the logged-in user's active session tokens.
Apart from enabling remote access, reconnaissance, and persistence, PowMix also facilitates...
Before attempting to establish persistence, PowMix performs several validation checks to ensure that another instance of the botnet is not running in the infected machine. It examines the process tree using Common Information Model (CIM) queries to identify its parent processes.
Newly emergent PowMix botnet has been leveraging randomized command-and-control beaconing intervals...
PowMix avoids persistent connections to the C2 server... Each request from PowMix to C2 is created by concatenating the base C2 domain with the Bot ID... PowMix establishes a Chrome User-Agent and configures the Accept-Language (en-US) and Accept-Encoding (gzip, deflate, br) headers.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet/backdoor delivered via phishing emails with a ZIP containing an LNK file and PowerShell loader. It runs in memory and enables remote access, reconnaissance, persistence, and remote command execution, including self-deletion and command-and-control migration.
Previously unreported PowerShell-based botnet that provides remote access, reconnaissance, persistence via scheduled tasks, dynamic C2 updates, jittered beaconing, and arbitrary remote code execution while evading detection through AMSI bypass and in-memory execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.