PowerPool

First seen
2018-09-01 00:00:00
Malware type
backdoor, trojan
Family
Malware family
Profile updated
2026-07-07 14:44:05

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:ua country_code:pl country_code:de country_code:cz

Context

PowerPool is a malware backdoor used in targeted attacks, primarily focusing on government and public sector organizations in Eastern Europe. It is known for exploiting Windows vulnerabilities to maintain persistence and execute malicious commands on compromised systems.

Detection coverage

  • 5 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Powerpool_Jul_2021_1 (yara-rule)
  • ARKBIRD_SOLG_MAL_Powerpool_Jul_2021_2 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Powerpool_STG1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Powerpool_STG2 (yara-rule)
  • MALPEDIA_Win_Powerpool_Auto (yara-rule)

Reports & references

  • ESET — Powerpool Malware Exploits Zero Day Vulnerability (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Powerpool (report)

External references