Poweliks
- First seen
- 2014-01-01 00:00:00
- Malware type
- trojan, botnet
- Family
- Malware family
- Profile updated
- 2026-07-07 15:16:09
Targeted industries: financial-services government-and-public-sector
Context
Poweliks is a fileless malware that maintains persistence by storing malicious scripts in the Windows registry. It is primarily used in financial and government sector attacks to execute remote commands and download additional malware.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Poweliks_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Poweliks (report)
- zscaler.com — Malvertising Targeting European Transit Users (report)
- thisissecurity.stormshield.com — Poweliks Command Line Confusion (report)
- gdatasoftware.com — 23947 Poweliks The Persistent Malware Without A File (report)