PowerShellRunner
- Malware type
- loader, downloader
- Family
- Malware family
- Last IoC activity
- 2026-07-11 07:38:32
- Profile updated
- 2026-07-07 13:19:50
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
PowerShellRunner is a fileless malware that leverages PowerShell scripts to execute payloads on a target system. It is often used as a loader and downloader for other malicious components in targeted attacks.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Powershellrunner_Auto (yara-rule)
Reports & references
- ESET — Turla Powershell Usage (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Powershellrunner (report)
- raw.githubusercontent.com — 2019 04 13 Possible Turla Powershell Implant.Ps1 (report)