Empire Downloader

First seen
2018-05-01 00:00:00
Malware type
downloader
Last IoC activity
2026-04-29 16:44:45
Profile updated
2026-07-07 12:36:23

Targeted industries: government-and-public-sector

Context

Empire Downloader is a PowerShell-based malware primarily used to download and execute additional payloads. It is typically utilized in targeted attacks against governmental and public sector organizations.

Reports & references

  • secureworks.com — Bronze Firestone (report)
  • Palo Alto Unit 42 — Obscureserpens (report)
  • secureworks.com — Gold Ulrick (report)
  • secureworks.com — Bronze Atlas (report)
  • MITRE ATT&CK — G0096 (report)
  • secureworks.com — Gold Heron (report)
  • secureworks.com — Gold Burlap (report)
  • lab52.io — Wirte Group Attacking The Middle East (report)
  • cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
  • secureworks.com — Gold Heron (report)
  • secureworks.com — Gold Drake (report)
  • thedfirreport.com — Pysa Mespinoza Ransomware (report)
  • CISA — Aa22 249A (report)
  • cyber.gov.au — Acsc Advisory 2020 008 Copy Paste Compromises (report)
  • Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
  • go.recordedfuture.com — Cta 2021 0107 (report)
  • cocomelonc.github.io — Malware Pers 1 (report)
  • jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
  • CISA — Aa20 275A (report)
  • paper.seebug.org — 1301 (report)
  • redcanary.com — Getsystem Offsec (report)
  • decoded.avast.io — Decoding Cobalt Strike Understanding Payloads (report)
  • Mandiant — Download (report)
  • cert.ssi.gouv.fr — Certfr 2023 Cti 009 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Empire Downloader (report)

External references