Empire Powershell

Malware updated 4 months ago (2024-05-04T18:56:31.978Z)
Download STIX
Preview STIX
Empire PowerShell is a type of malware, harmful software designed to exploit and damage computer systems. It can infiltrate a system through suspicious downloads, emails, or websites, often unbeknownst to the user. Once inside, it can steal personal information, disrupt operations, or even hold data hostage for ransom. This particular malware was detected as early as September 2017, according to Daron Hartvigsen, a cybersecurity specialist for DFIN. Further Empire PowerShell activity was detected in November 2019, indicating continued unauthorized intrusions. In 2020, the group responsible for the Empire PowerShell attacks switched their tactics, moving away from the Empire PowerShell framework due to its lack of updates from the original creators. Instead, they began using CobaltStrike for lateral movement activity. This set of domains is used as a Command & Control (C&C) center by the group, leveraging a custom loader to execute their malicious activities. A customized version of the CobaltStrike loader has been observed, which is possibly intended as a replacement for the previously used Empire PowerShell framework. This shift in tactics suggests an evolution in the group's strategy, making it crucial for organizations to stay updated with the latest cybersecurity threats and mitigation strategies. The continued detection of Empire malware activity underscores the persistent nature of these threats and the importance of robust cybersecurity measures.
Description last updated: 2023-09-19T01:51:10.580Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Empire Powershell Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
a year ago
Russian infosec boss gets nine years for hack-and-trade op
CERT-EU
a year ago
Russian infosec boss gets nine years for hack-and-trade op
GovCERT CH
2 years ago
Severe Ransomware Attacks Against Swiss SMEs
MITRE
2 years ago
WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group