Empire Downloader
- First seen
- 2018-05-01 00:00:00
- Malware type
- downloader
- Last IoC activity
- 2026-04-29 16:44:45
- Profile updated
- 2026-07-07 12:36:23
Targeted industries: government-and-public-sector
Context
Empire Downloader is a PowerShell-based malware primarily used to download and execute additional payloads. It is typically utilized in targeted attacks against governmental and public sector organizations.
Reports & references
- secureworks.com — Bronze Firestone (report)
- Palo Alto Unit 42 — Obscureserpens (report)
- secureworks.com — Gold Ulrick (report)
- secureworks.com — Bronze Atlas (report)
- MITRE ATT&CK — G0096 (report)
- secureworks.com — Gold Heron (report)
- secureworks.com — Gold Burlap (report)
- lab52.io — Wirte Group Attacking The Middle East (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- secureworks.com — Gold Heron (report)
- secureworks.com — Gold Drake (report)
- thedfirreport.com — Pysa Mespinoza Ransomware (report)
- CISA — Aa22 249A (report)
- cyber.gov.au — Acsc Advisory 2020 008 Copy Paste Compromises (report)
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- go.recordedfuture.com — Cta 2021 0107 (report)
- cocomelonc.github.io — Malware Pers 1 (report)
- jsac.jpcert.or.jp — Jsac2024 1 9 Takeda Furukawa En (report)
- CISA — Aa20 275A (report)
- paper.seebug.org — 1301 (report)
- redcanary.com — Getsystem Offsec (report)
- decoded.avast.io — Decoding Cobalt Strike Understanding Payloads (report)
- Mandiant — Download (report)
- cert.ssi.gouv.fr — Certfr 2023 Cti 009 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Empire Downloader (report)