PowerPool — APT Profile
PowerPool is the label ESET attached to a small intrusion set that in 2018 became one of the first operators to field CVE-2018-8440, a Windows Task Scheduler flaw in which the SchRpcSetSecurity call skipped a permissions check and let any local user rewrite files in the Windows Tasks directory to reach SYSTEM on Windows 7 through 10. Exploit code had been dumped publicly by the researcher using the handle SandboxEscaper on 27 August 2018; ESET saw the group deploying it about two days later, recompiled from a lightly altered copy of that source rather than run as the released binary. Its toolkit leaned heavily on PowerShell, pairing a lightweight reconnaissance backdoor and a fuller second-stage implant with commodity post-exploitation kit including PowerSploit, SMBExec, Quarks PwDump and FireMaster. ESET reported only a handful of victims, in Chile, Germany, India, the Philippines, Poland, Russia, Ukraine, the United Kingdom and the United States. Kaspersky later folded the same operator into a cluster it calls IAmTheKing, tying it to a backdoor lineage — KingOfHearts, QueenOfHearts, QueenOfClubs, and the SlothfulMedia variant US-CERT documented in October 2020 — in use since roughly 2014 and aimed overwhelmingly at Russian government, defence, university and energy organisations, an emphasis Kaspersky judged consistent with state sponsorship.Also tracked as
IAmTheKing
Tools & malware
- win.slothfulmedia Backdoor