POWERSTAR
- First seen
- 2021-06-15 00:00:00
- Malware type
- rat, backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 14:39:00
Targeted industries: government-and-public-sector defense-and-aerospace energy-and-utilities
Targeted regions: country_code:us country_code:ru country_code:cn
Context
POWERSTAR is a remote access tool commonly used in cyber espionage campaigns targeting government agencies and critical infrastructure sectors. It provides attackers with the ability to execute commands and gather intelligence from compromised systems.
Detection coverage
- 8 YARA rules
Detection rules
- VOLEXITY_Apt_Win_Powerstar_Persistence_Batch (yara-rule)
- VOLEXITY_Apt_Win_Powerstar_Memonly (yara-rule)
- VOLEXITY_Apt_Win_Powerstar_Logmessage (yara-rule)
- VOLEXITY_Apt_Win_Powerstar_Lnk (yara-rule)
- VOLEXITY_Apt_Win_Powerstar_Decrypt_Function (yara-rule)
- VOLEXITY_Apt_Win_Powerstar (yara-rule)
- VOLEXITY_Apt_Malware_Vbs_Basicstar_A (yara-rule)
- VOLEXITY_Apt_Malware_Ps1_Powerstar_Generic (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Ps1.Powerstar (report)
- volexity.com — Charming Kitten Updates Powerstar With An Interplanetary Twist (report)