PowerWare
Aliases: PoshCoder
- First seen
- 2016-03-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 15:42:58
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality
Context
PowerWare, also known as PoshCoder, is a ransomware variant that uses PowerShell scripts for execution. It primarily targets industries such as financial services, healthcare, and retail, leveraging open-source tools to encrypt files and demand ransom.
Reports & references
- github.com — Powerware Decrypt.Py (report)
- download.bleepingcomputer.com — Powerlockydecrypter.Zip (report)
- carbonblack.com — Threat Alert Powerware New Ransomware Written In Powershell Targets Organizations Via Microsoft Word (report)
- researchcenter.paloaltonetworks.com — Unit42 Powerware Ransomware Spoofing Locky Malware Family (report)
- id-ransomware.blogspot.com — Powerware Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Ps1.Powerware (report)
- blog.cylance.com — Ransomware Update Todays Bountiful Cornucopia Of Extortive Threats (report)