PowerCat

Malware type
trojan
Last IoC activity
2026-06-28 19:14:45
Profile updated
2026-07-07 12:59:33

Context

PowerCat is a simple, open-source PowerShell tool that functions similarly to the netcat utility. It's used for relaying traffic and can be utilized by attackers for data exfiltration or as a reverse shell.

Detection coverage

  • 1 YARA rules

Detection rules

  • SIGNATURE_BASE_HKTL_PS1_Powercat_Mar21 (yara-rule)

Reports & references

  • Microsoft — Hafnium Targeting Exchange Servers (report)
  • cyborgsecurity.com — You Dont Know The Hafnium Of It (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Powercat (report)
  • twitter.com — 1141540229951709184 (report)

External references