PowerStallion — Malware Profile
PowerStallion is a lightweight PowerShell backdoor used by Turla, possibly as a recovery access tool to install other backdoors.
MITRE ATT&CK techniques (5)
- T1027 Obfuscated Files or Information
- T1057 Process Discovery
- T1059.001 PowerShell
- T1070.006 Timestomp
- T1102.002 Bidirectional Communication