PowerWare

Aliases: PoshCoder

First seen
2016-03-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 15:42:58

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

PowerWare, also known as PoshCoder, is a ransomware variant that uses PowerShell scripts for execution. It primarily targets industries such as financial services, healthcare, and retail, leveraging open-source tools to encrypt files and demand ransom.

Reports & references

  • github.com — Powerware Decrypt.Py (report)
  • download.bleepingcomputer.com — Powerlockydecrypter.Zip (report)
  • carbonblack.com — Threat Alert Powerware New Ransomware Written In Powershell Targets Organizations Via Microsoft Word (report)
  • researchcenter.paloaltonetworks.com — Unit42 Powerware Ransomware Spoofing Locky Malware Family (report)
  • id-ransomware.blogspot.com — Powerware Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Ps1.Powerware (report)
  • blog.cylance.com — Ransomware Update Todays Bountiful Cornucopia Of Extortive Threats (report)

External references