POWERSOURCE

Malware updated 4 months ago (2024-05-04T18:55:54.630Z)
Download STIX
Preview STIX
Powersource is a newly discovered malware family, classified as a backdoor, that has been spotted by cybersecurity firm FireEye iSIGHT Intelligence. Malware is a dangerous program that can enter your computer or device through downloads, emails, or websites, and can steal personal information or disrupt operations. In some cases, it can even hold your data for ransom. Powersource appears to be a heavily modified version of the tool DNS_TXT_Pwnage and is designed to evade detection. FireEye iSIGHT Intelligence has investigated various topics related to this malware, including the POWERSOURCE and TEXTMATE malware families. The MySIGHT Portal contains additional information on these investigations. Cobalt Strike Beacon payloads have been observed being delivered via Powersource, which can further infect the victim machine. Additionally, Powersource has been used to download Textmate, a second-stage PowerShell backdoor, to increase its reach and impact. Overall, Powersource is a highly sophisticated and dangerous malware family that users should be aware of. It is crucial to take proactive measures to protect yourself from such threats, including regularly updating your operating system and applications, avoiding suspicious downloads, and using reputable antivirus software.
Description last updated: 2023-06-23T18:33:48.555Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the POWERSOURCE Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago
FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings « FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings