POWERPLANT

First seen
2018-06-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 13:22:02

Targeted industries: financial-services retail-and-hospitality

Context

This powershell code is a PowerShell written backdoor used by FIN7. Regarding to Mandiant that is was revealed to be a "vast backdoor framework with a breadth of capabilities, depending on which modules are delivered from the C2 server."

Reports & references

  • Mandiant — Evolution Of Fin7 (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Powerplant (report)

External references