Powersniff
Aliases: PUNCHBUGGY
- First seen
- 2016-03-01 00:00:00
- Malware type
- trojan, downloader
- Profile updated
- 2026-07-07 12:50:59
Targeted industries: financial-services government-and-public-sector
Targeted regions: country_code:us country_code:de country_code:jp
Context
A malware of the gozi group, developed on the base of isfb. It uses Office Macros and PowerShell in documents distributed in e-mail messages.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Powersniff_Auto (yara-rule)
Reports & references
- afyonluoglu.org — 2017%20Fireeye%20M Trends%20Report (report)
- Mandiant — Rpt M Trends 2017 (report)
- lokalhost.pl — Gozi Tree.Txt (report)
- atr-blog.gigamon.com — Abadbabe 8Badf00D Discovering Badhatch And A Detailed Look At Fin8S Tooling (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Powersniff (report)
- Palo Alto Unit 42 — Powersniff Malware Used In Macro Based Attacks (report)