POWERTRASH
- First seen
- 2018-01-01 00:00:00
- Malware type
- dropper
- Profile updated
- 2026-07-07 13:12:22
Targeted industries: retail-and-hospitality financial-services technology-and-telecommunications
Context
This PowerShell written malware is an in-memory dropper used by FIN7 to execute the included/embedded payload. According to Mandiant's blog article: "POWERTRASH is a uniquely obfuscated iteration of a shellcode invoker included in the PowerSploit framework available on GitHub."
Reports & references
- rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
- Mandiant — Evolution Of Fin7 (report)
- recordedfuture.com — Grayalpha Uses Diverse Infection Vectors Deploy Powernet Loader Netsupport Rat (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Powertrash (report)
- Mandiant — Evolution Of Fin7 (report)