Power Loader
MITRE ATT&CK: S0177 View on attack.mitre.org
- Malware type
- downloader, loader
- Family
- Malware family
- Related IoCs
- 6 (4 malicious)
- Last IoC activity
- 2026-08-23 02:31:25
- Profile updated
- 2026-07-07 15:16:12
Targeted industries: financial-services
Context
Power Loader is modular code sold in the cybercrime market used as a downloader in malware families such as Carberp, Redyms and Gapz.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to Power Loader (S0177). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| URL | http://176.46.152.47/bot.exe | 2025-11-02 | 2 |
| URL | http://176.46.152.46/bot.exe | 2025-11-02 | 2 |
| URL | http://176.46.152.47/dropper64.exe | 2025-09-01 | 1 |
| URL | http://176.46.152.46/dropper64.exe | 2025-09-01 | 2 |
Detection coverage
- 1 Sigma rules
Malware & tools used
- Extra Window Memory Injection (attack-pattern)
Reports & references
- malwaretech.com — Powerloader Injection Something Truly (report)
- MITRE ATT&CK — S0177 (report)
- ESET — Gapz And Redyms Droppers Based On Power Loader Code (report)