POWERSTAR

First seen
2021-06-15 00:00:00
Malware type
rat, backdoor
Family
Malware family
Profile updated
2026-07-07 14:39:00

Targeted industries: government-and-public-sector defense-and-aerospace energy-and-utilities

Targeted regions: country_code:us country_code:ru country_code:cn

Context

POWERSTAR is a remote access tool commonly used in cyber espionage campaigns targeting government agencies and critical infrastructure sectors. It provides attackers with the ability to execute commands and gather intelligence from compromised systems.

Detection coverage

  • 8 YARA rules

Detection rules

  • VOLEXITY_Apt_Win_Powerstar_Persistence_Batch (yara-rule)
  • VOLEXITY_Apt_Win_Powerstar_Memonly (yara-rule)
  • VOLEXITY_Apt_Win_Powerstar_Logmessage (yara-rule)
  • VOLEXITY_Apt_Win_Powerstar_Lnk (yara-rule)
  • VOLEXITY_Apt_Win_Powerstar_Decrypt_Function (yara-rule)
  • VOLEXITY_Apt_Win_Powerstar (yara-rule)
  • VOLEXITY_Apt_Malware_Vbs_Basicstar_A (yara-rule)
  • VOLEXITY_Apt_Malware_Ps1_Powerstar_Generic (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Ps1.Powerstar (report)
  • volexity.com — Charming Kitten Updates Powerstar With An Interplanetary Twist (report)

External references