POWERTON
MITRE ATT&CK: S0371 View on attack.mitre.org
Aliases: POWERTON
- First seen
- 2018-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:42:39
Targeted industries: defense-and-aerospace energy-and-utilities
Targeted regions: country_code:sa
Context
POWERTON is a custom PowerShell backdoor first observed in 2018. It has typically been deployed as a late-stage backdoor by APT33. At least two variants of the backdoor have been identified, with the later version containing improved functionality.
Detection coverage
- 280 Sigma rules
Malware & tools used
- Symmetric Cryptography (attack-pattern)
- Web Protocols (attack-pattern)
- PowerShell (attack-pattern)
- Security Account Manager (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
Used by threat actors
- APT33 (threat-actor)
Reports & references
- secureworks.com — Cobalt Trinity (report)
- Microsoft — Inside Microsoft Threat Protection Mapping Attack Chains From Cloud To Endpoint (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Powerton (report)
- Mandiant — Scandalous External Detection Using Network Scan Data And Automation (report)
- Mandiant — Overruled Containing A Potentially Destructive Adversary (report)
- Broadcom/Symantec — 2019 062513 4935 99 (report)
- blog.telsy.com — Meeting Powerband The Apt33 Net Powerton Variant (report)
- norfolkinfosec.com — Apt33 Powershell Malware (report)
- MITRE ATT&CK — S0371 (report)