POWERSOURCE
MITRE ATT&CK: S0145 View on attack.mitre.org
Aliases: DNSMessenger, POWERSOURCE
- First seen
- 2017-02-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:45:08
Targeted industries: financial-services government-and-public-sector
Targeted regions: country_code:us
Context
POWERSOURCE is a PowerShell backdoor that is a heavily obfuscated and modified version of the publicly available tool DNS_TXT_Pwnage. It was observed in February 2017 in spearphishing campaigns against personnel involved with United States Securities and Exchange Commission (SEC) filings at various organizations. The malware was delivered when macros were enabled by the victim and a VBS script was dropped.
Detection coverage
- 321 Sigma rules
Malware & tools used
- PowerShell (attack-pattern)
- Query Registry (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- NTFS File Attributes (attack-pattern)
- DNS (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Used by threat actors
- FIN7 (threat-actor)
Related threat objects
- DNSMessenger (malware)
- DNSMessenger (malware)
Reports & references
- Mandiant — Fin7 Spear Phishing (report)
- web.archive.org — Fin7 Spear Phishing (report)
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
- cocomelonc.github.io — Malware Tricks 35 (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Powersource (report)
- Cisco Talos — Dnsmessenger (report)
- MITRE ATT&CK — S0145 (report)