Empire

MITRE ATT&CK: S0363 View on attack.mitre.org

Aliases: EmPyre, PowerShell Empire, Empire

First seen
2015-08-31 00:00:00
Malware type
rat, backdoor
Family
Malware family
Operating systems
linux, macos, windows
Related IoCs
4 (4 malicious)
Last IoC activity
2026-07-11 07:38:32
Profile updated
2026-07-07 15:30:45

Targeted industries: government-and-public-sector defense-and-aerospace financial-services technology-and-telecommunications

Context

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to Empire (S0363). The 4 most recently updated:

TypeIndicatorUpdatedSources
file sample 53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce 2026-07-11 3
file sample 2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.bin 2026-05-21 2
file sample OneDriveUpdate.ps1 2025-12-01 1
file sample 13abc0b07a0fd203053e9dcfea6f490d.vbs 2025-10-15 2

Detection coverage

  • 5 YARA rules
  • 995 Sigma rules

Malware & tools used

  • Video Capture (attack-pattern)
  • Distributed Component Object Model (attack-pattern)
  • Name Resolution Poisoning and SMB Relay (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • Keylogging (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Local Account (attack-pattern)
  • Screen Capture (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Group Policy Modification (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Accessibility Features (attack-pattern)
  • Automated Collection (attack-pattern)
  • Keychain (attack-pattern)
  • Group Policy Discovery (attack-pattern)
  • Domain Account (attack-pattern)
  • Security Support Provider (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Backdoor_Powershellempire_Batlauchers (yara-rule)
  • SEKOIA_Backdoor_Powershellempire_Sharpire (yara-rule)
  • SEKOIA_Gen_Empire_Onedrive_Stager (yara-rule)
  • SEKOIA_Backdoor_Powershellempire_Python (yara-rule)
  • SEKOIA_Backdoor_Powershellempire_Csharp (yara-rule)

Reports & references

  • ncsc.gov.uk — Joint Report On Publicly Available Hacking Tools (report)
  • MITRE ATT&CK — S0363 (report)
  • github.com — Empire (report)
  • github.com — Attck Empire (report)

External references