POWERTON — Malware Profile

POWERTON is a custom PowerShell backdoor first observed in 2018. It has typically been deployed as a late-stage backdoor by APT33. At least two variants of the backdoor have been identified, with the later version containing improved functionality.

MITRE ATT&CK techniques (6)

IntelFusions coverage

Attributed threat actors

Read the full analysis on IntelFusions