POWERTON — Malware Profile
POWERTON is a custom PowerShell backdoor first observed in 2018. It has typically been deployed as a late-stage backdoor by APT33. At least two variants of the backdoor have been identified, with the later version containing improved functionality.
MITRE ATT&CK techniques (6)
- T1003.002 Security Account Manager
- T1059.001 PowerShell
- T1071.001 Web Protocols
- T1546.003 Windows Management Instrumentation Event Subscription
- T1547.001 Registry Run Keys / Startup Folder
- T1573.001 Symmetric Cryptography