POWERSOURCE

MITRE ATT&CK: S0145 View on attack.mitre.org

Aliases: DNSMessenger, POWERSOURCE

First seen
2017-02-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:45:08

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us

Context

POWERSOURCE is a PowerShell backdoor that is a heavily obfuscated and modified version of the publicly available tool DNS_TXT_Pwnage. It was observed in February 2017 in spearphishing campaigns against personnel involved with United States Securities and Exchange Commission (SEC) filings at various organizations. The malware was delivered when macros were enabled by the victim and a VBS script was dropped.

Detection coverage

  • 321 Sigma rules

Malware & tools used

  • PowerShell (attack-pattern)
  • Query Registry (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • DNS (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

  • FIN7 (threat-actor)

Related threat objects

Reports & references

  • Mandiant — Fin7 Spear Phishing (report)
  • web.archive.org — Fin7 Spear Phishing (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
  • cocomelonc.github.io — Malware Tricks 35 (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Powersource (report)
  • Cisco Talos — Dnsmessenger (report)
  • MITRE ATT&CK — S0145 (report)

External references