PowerStallion

MITRE ATT&CK: S0393 View on attack.mitre.org

Aliases: PowerStallion

First seen
2018-11-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:19:53

Targeted industries: government-and-public-sector

Targeted regions: country_code:de country_code:ru

Context

PowerStallion is a lightweight PowerShell backdoor used by Turla, possibly as a recovery access tool to install other backdoors.

Detection coverage

  • 280 Sigma rules

Malware & tools used

  • Bidirectional Communication (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • PowerShell (attack-pattern)
  • Timestomp (attack-pattern)
  • Process Discovery (attack-pattern)

Used by threat actors

Reports & references

  • ESET — Turla Powershell Usage (report)
  • MITRE ATT&CK — S0393 (report)

External references