Empire
MITRE ATT&CK: S0363 View on attack.mitre.org
Aliases: EmPyre, PowerShell Empire, Empire
- First seen
- 2015-08-31 00:00:00
- Malware type
- rat, backdoor
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Related IoCs
- 4 (4 malicious)
- Last IoC activity
- 2026-07-11 07:38:32
- Profile updated
- 2026-07-07 15:30:45
Targeted industries: government-and-public-sector defense-and-aerospace financial-services technology-and-telecommunications
Context
Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to Empire (S0363). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 53b55ab8b1dd2d78709f93399db598c3172ab1c8b9a7a138f1f4a4b3a99b35ce | 2026-07-11 | 3 |
| file sample | 2d5158cd0432f58c49293cfd91b56b92f14fa43cece9194fcadf1b3e4bb99257.bin | 2026-05-21 | 2 |
| file sample | OneDriveUpdate.ps1 | 2025-12-01 | 1 |
| file sample | 13abc0b07a0fd203053e9dcfea6f490d.vbs | 2025-10-15 | 2 |
Detection coverage
- 5 YARA rules
- 995 Sigma rules
Malware & tools used
- Video Capture (attack-pattern)
- Distributed Component Object Model (attack-pattern)
- Name Resolution Poisoning and SMB Relay (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- PowerShell (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Keylogging (attack-pattern)
- Command Obfuscation (attack-pattern)
- Local Account (attack-pattern)
- Screen Capture (attack-pattern)
- Network Service Discovery (attack-pattern)
- Credentials In Files (attack-pattern)
- Archive Collected Data (attack-pattern)
- Group Policy Modification (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- System Information Discovery (attack-pattern)
- Clipboard Data (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Automated Exfiltration (attack-pattern)
- Accessibility Features (attack-pattern)
- Automated Collection (attack-pattern)
- Keychain (attack-pattern)
- Group Policy Discovery (attack-pattern)
- Domain Account (attack-pattern)
- Security Support Provider (attack-pattern)
Used by threat actors
- Wizard Spider (threat-actor)
- Sandworm Team (threat-actor)
- Indrik Spider (threat-actor)
- FIN10 (threat-actor)
- Turla (threat-actor)
- WIRTE (threat-actor)
- HEXANE (threat-actor)
- APT19 (threat-actor)
- APT41 (threat-actor)
- LazyScripter (threat-actor)
- Play (threat-actor)
- Silence (threat-actor)
- CopyKittens (threat-actor)
- APT33 (threat-actor)
- Leviathan (threat-actor)
- MuddyWater (threat-actor)
- FIN13 (threat-actor)
- Frankenstein (campaign)
Detection rules
- SEKOIA_Backdoor_Powershellempire_Batlauchers (yara-rule)
- SEKOIA_Backdoor_Powershellempire_Sharpire (yara-rule)
- SEKOIA_Gen_Empire_Onedrive_Stager (yara-rule)
- SEKOIA_Backdoor_Powershellempire_Python (yara-rule)
- SEKOIA_Backdoor_Powershellempire_Csharp (yara-rule)
Reports & references
- ncsc.gov.uk — Joint Report On Publicly Available Hacking Tools (report)
- MITRE ATT&CK — S0363 (report)
- github.com — Empire (report)
- github.com — Attck Empire (report)