Power Loader

MITRE ATT&CK: S0177 View on attack.mitre.org

Malware type
downloader, loader
Family
Malware family
Related IoCs
6 (4 malicious)
Last IoC activity
2026-08-23 02:31:25
Profile updated
2026-07-07 15:16:12

Targeted industries: financial-services

Context

Power Loader is modular code sold in the cybercrime market used as a downloader in malware families such as Carberp, Redyms and Gapz.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to Power Loader (S0177). The 4 most recently updated:

TypeIndicatorUpdatedSources
URL http://176.46.152.47/bot.exe 2025-11-02 2
URL http://176.46.152.46/bot.exe 2025-11-02 2
URL http://176.46.152.47/dropper64.exe 2025-09-01 1
URL http://176.46.152.46/dropper64.exe 2025-09-01 2

Detection coverage

  • 1 Sigma rules

Malware & tools used

  • Extra Window Memory Injection (attack-pattern)

Reports & references

  • malwaretech.com — Powerloader Injection Something Truly (report)
  • MITRE ATT&CK — S0177 (report)
  • ESET — Gapz And Redyms Droppers Based On Power Loader Code (report)

External references