PowerPool
- First seen
- 2018-09-01 00:00:00
- Malware type
- backdoor, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 14:44:05
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:ua country_code:pl country_code:de country_code:cz
Context
PowerPool is a malware backdoor used in targeted attacks, primarily focusing on government and public sector organizations in Eastern Europe. It is known for exploiting Windows vulnerabilities to maintain persistence and execute malicious commands on compromised systems.
Detection coverage
- 5 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Powerpool_Jul_2021_1 (yara-rule)
- ARKBIRD_SOLG_MAL_Powerpool_Jul_2021_2 (yara-rule)
- DITEKSHEN_MALWARE_Win_Powerpool_STG1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Powerpool_STG2 (yara-rule)
- MALPEDIA_Win_Powerpool_Auto (yara-rule)
Reports & references
- ESET — Powerpool Malware Exploits Zero Day Vulnerability (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Powerpool (report)