Poweliks

First seen
2014-01-01 00:00:00
Malware type
trojan, botnet
Family
Malware family
Profile updated
2026-07-07 15:16:09

Targeted industries: financial-services government-and-public-sector

Context

Poweliks is a fileless malware that maintains persistence by storing malicious scripts in the Windows registry. It is primarily used in financial and government sector attacks to execute remote commands and download additional malware.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Poweliks_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Poweliks (report)
  • zscaler.com — Malvertising Targeting European Transit Users (report)
  • thisissecurity.stormshield.com — Poweliks Command Line Confusion (report)
  • gdatasoftware.com — 23947 Poweliks The Persistent Malware Without A File (report)

External references