Powersniff

Aliases: PUNCHBUGGY

First seen
2016-03-01 00:00:00
Malware type
trojan, downloader
Profile updated
2026-07-07 12:50:59

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us country_code:de country_code:jp

Context

A malware of the gozi group, developed on the base of isfb. It uses Office Macros and PowerShell in documents distributed in e-mail messages.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Powersniff_Auto (yara-rule)

Reports & references

  • afyonluoglu.org — 2017%20Fireeye%20M Trends%20Report (report)
  • Mandiant — Rpt M Trends 2017 (report)
  • lokalhost.pl — Gozi Tree.Txt (report)
  • atr-blog.gigamon.com — Abadbabe 8Badf00D Discovering Badhatch And A Detailed Look At Fin8S Tooling (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Powersniff (report)
  • Palo Alto Unit 42 — Powersniff Malware Used In Macro Based Attacks (report)

External references