Iran-linked APT35 (also tracked as Phosphorus and Charming Kitten) was reported using a newly documented PowerShell backdoor called PowerLess in espionage intrusions, with researchers also identifying overlaps with the Memento ransomware operation. Cybereason said the malware executes PowerShell inside a .NET context rather than spawning powershell.exe, helping it evade some PowerShell-focused defenses, and supports encrypted command-and-control, command execution, process termination, keylogging, browser-data theft, and delivery of additional payloads. The activity was tied to exploitation of ProxyShell, Log4Shell, and in related reporting CVE-2021-21972 in VMware vCenter, alongside post-compromise behavior including reconnaissance, credential dumping, persistence, lateral movement, and use of FRP-based proxy tooling.
Technical analysis of later APT35 samples described a multi-stage infection chain beginning with a malicious .LNK file disguised as a Microsoft Edge shortcut, opening a PDF decoy, loading malicious DLLs, and ultimately deploying the PowerLess component for follow-on theft and surveillance. Researchers highlighted custom TEA32-based string decryption and abuse of Windows COM to invoke functionality from a .NET DLL in ways that reduce visibility for analysts and some sandbox tools. Across the reporting, shared infrastructure, naming conventions, automatically generated strings, overlapping timelines, and an IP address cited as 91.214.124.143 were presented as evidence supporting a possible operational link between APT35 activity and Memento ransomware.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
A presentation titled “APT35: The Silent Adversary Under the Radar” was delivered at Security Bootcamp 2025 in Hue City, Vietnam, analyzing an APT35 infection chain that used a malicious LNK, decoy PDF, DLL stages, and the PowerLess component for follow-on theft.
The references say APT35 deployed a previously undocumented PowerShell backdoor named CharmPower in attacks exploiting Log4Shell, with one source anchoring this activity to January 2022 and another to mid-January.
In November 2021, Microsoft Threat Intelligence Center said it was tracking six Iranian threat groups involved in ransomware deployment and data exfiltration.
A joint US-UK cybersecurity advisory issued in November 2021 warned about Iranian hacking groups targeting Microsoft Exchange and Fortinet servers.
The references place the emergence of the Memento ransomware operation in 2021, with one source specifying it had been active since April 2021.
BleepingComputer reports that in a November 2021 statement, Microsoft Threat Intelligence Center said six Iranian threat groups had been deploying ransomware and exfiltrating data since as far back as September 2020.
The references state that APT35 targeted medical research organizations in the United States and Israel in late 2020.
Public reporting cited in the references says APT35 targeted academic researchers in the United States, France, and the Middle East in 2019.
While investigating PowerLess activity, Cybereason identified overlaps in TTPs, generated strings, domains, and IP-linked infrastructure that suggested a possible connection between APT35/Phosphorus and the Memento ransomware operation.
Cybereason reported increased activity by APT35 and identified a previously undocumented PowerShell-based backdoor called PowerLess that runs in a .NET context, supports encrypted C2, command execution, process killing, keylogging, and browser-data theft.
Sophos researchers reported that Memento operators moved from a Python-based ransomware strain to copying victim files into password-protected WinRAR archives, encrypting the archive password, and deleting originals.
Researchers observed the Memento ransomware operation exploiting CVE-2021-21972, a critical pre-authentication remote code execution flaw in VMware vCenter Server, to gain initial access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
kienmanowar.wordpress.com
Open sourcecybereason.com
Open sourcesecurityaffairs.co
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.