Attackers can abuse PowerShell profile scripts to gain persistence on Windows by placing malicious commands in profile.ps1, causing a payload to run automatically whenever a user starts a PowerShell session. A proof-of-concept example showed a helper program creating the WindowsPowerShell profile directory and writing a command that launched a payload, which then executed with powershell.exe as its parent process. The technique has also been linked to real-world activity, with reports noting Turla has used PowerShell profile persistence in the wild.
Microsoft’s documentation shows why the method is effective: PowerShell supports multiple profile locations and scopes, including per-user and all-users profiles and host-specific variants, all of which can execute at startup depending on configuration and privileges. The same documentation also outlines key defensive controls, including enforcing signed scripts through execution policy, using pwsh -NoProfile to prevent profile loading, and understanding that profile behavior differs across platforms and remote sessions, which can affect both attacker tradecraft and defender response.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft Learn publishes documentation describing how PowerShell profiles work, their storage locations and scopes, execution order, execution policy constraints, and the use of pwsh -NoProfile to bypass profile loading. The document also notes that profiles do not automatically run in remote sessions and explains MSIX-related profile limitations.
A blog post demonstrates a Windows persistence technique that writes a payload path into the current user's PowerShell profile so the payload executes when PowerShell starts. The author also presents a C++ helper program, pers.exe, to create the profile directory and write the malicious command into profile.ps1.
The content states that Turla has used PowerShell profile persistence as a real-world technique. No specific date is provided for when this activity occurred.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.