PowerShellRunner

Malware type
loader, downloader
Family
Malware family
Last IoC activity
2026-07-11 07:38:32
Profile updated
2026-07-07 13:19:50

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Context

PowerShellRunner is a fileless malware that leverages PowerShell scripts to execute payloads on a target system. It is often used as a loader and downloader for other malicious components in targeted attacks.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Powershellrunner_Auto (yara-rule)

Reports & references

  • ESET — Turla Powershell Usage (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Powershellrunner (report)
  • raw.githubusercontent.com — 2019 04 13 Possible Turla Powershell Implant.Ps1 (report)

External references