PowerShower

MITRE ATT&CK: S0441 View on attack.mitre.org

Aliases: PowerShower

Malware type
backdoor, downloader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:53:46

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

PowerShower is a PowerShell backdoor used by Inception for initial reconnaissance and to download and execute second stage payloads.

Detection coverage

  • 4 YARA rules
  • 457 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Process Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Web Protocols (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Hidden Window (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Visual Basic (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Cloudatlas_Powershower_Obfuscated (yara-rule)
  • SEKOIA_Apt_Cloudatlas_Powershower_Module (yara-rule)
  • SEKOIA_Apt_Cloudatlas_Powershower_Variant (yara-rule)
  • SEKOIA_Apt_Cloudatlas_Powershower_Clean (yara-rule)

Reports & references

  • Palo Alto Unit 42 — Unit42 Inception Attackers Target Europe Year Old Office Vulnerability (report)
  • Kaspersky — 92016 (report)
  • Palo Alto Unit 42 — Clean Ursa (report)
  • MITRE ATT&CK — G0100 (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Powershower (report)
  • MITRE ATT&CK — S0441 (report)

External references