POWERTRASH

First seen
2018-01-01 00:00:00
Malware type
dropper
Profile updated
2026-07-07 13:12:22

Targeted industries: retail-and-hospitality financial-services technology-and-telecommunications

Context

This PowerShell written malware is an in-memory dropper used by FIN7 to execute the included/embedded payload. According to Mandiant's blog article: "POWERTRASH is a uniquely obfuscated iteration of a shellcode invoker included in the PowerSploit framework available on GitHub."

Reports & references

  • rewterz.com — Rewterz Threat Alert Widely Abused Msix App Installer Disabled By Microsoft Active Iocs (report)
  • Mandiant — Evolution Of Fin7 (report)
  • recordedfuture.com — Grayalpha Uses Diverse Infection Vectors Deploy Powernet Loader Netsupport Rat (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Powertrash (report)
  • Mandiant — Evolution Of Fin7 (report)

External references