PowerWare is a PowerShell-based ransomware family observed targeting Windows users. It is notable for abusing a legitimate administrative framework to execute malicious logic, aligning with broader fileless and low-file-footprint tradecraft that uses PowerShell to download, launch, or run payloads while reducing reliance on traditional executable files. PowerWare has been associated with delivery through malicious Microsoft Word documents, indicating document-based social engineering as an infection vector. In reporting on malicious PowerShell abuse, PowerWare has been cited alongside other malware families that leverage PowerShell for execution and payload delivery. Its use of PowerShell places it within a wider trend of attackers exploiting built-in Windows tooling for defense evasion and post-compromise activity. High-confidence reporting supports its classification as ransomware targeting Windows environments; additional operational details such as specific encryption workflow, persistence mechanisms, or actor attribution are not currently available from the supplied information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family mentioned as using PowerShell abuse techniques.
Next: PowerWare Ransomware Spoofing Locky Malware Family
A ransomware family written in PowerShell and delivered via a malicious Microsoft Word document.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.