PowerExchange — Malware Profile
PowerExchange is a PowerShell backdoor that has been used by OilRig since at least 2023 including against government targets in the Middle East.
MITRE ATT&CK techniques (5)
- T1041 Exfiltration Over C2 Channel
- T1059.001 PowerShell
- T1071.003 Mail Protocols
- T1105 Ingress Tool Transfer
- T1140 Deobfuscate/Decode Files or Information