POWERPLANT
- First seen
- 2018-06-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 13:22:02
Targeted industries: financial-services retail-and-hospitality
Context
This powershell code is a PowerShell written backdoor used by FIN7. Regarding to Mandiant that is was revealed to be a "vast backdoor framework with a breadth of capabilities, depending on which modules are delivered from the C2 server."
Reports & references
- Mandiant — Evolution Of Fin7 (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Powerplant (report)