TEXTMATE — Malware Profile

TEXTMATE is a second-stage PowerShell backdoor that is memory-resident. It was observed being used along with POWERSOURCE in February 2017.

MITRE ATT&CK techniques (2)

Attributed threat actors

Read the full analysis on IntelFusions