p0wnyshell is a PowerShell-based backdoor first publicly documented by FireEye in December 2020 during the SolarWinds supply-chain attack, where it was deployed as a post-exploitation tool by the threat group tracked as UNC2452 (also known as NOBELIUM or APT29). It belongs to the category of remote access trojans (RATs) and is used for stealthy command-and-control (C2) operations within compromised environments.
p0wnyshell executes entirely in memory using obfuscated PowerShell scripts to evade traditional file-based detection. It communicates over HTTP or HTTPS to attacker-controlled C2 servers, using encrypted payloads and dynamic DLL loading to blend into legitimate traffic. The malware can download and execute additional payloads, upload exfiltrated data, and run arbitrary system commands with elevated privileges. Persistence is achieved via scheduled tasks or registry run keys, and it employs defense evasion through PowerShell logging bypasses and AMSI (Anti-Malware Scan Interface) patching, as detailed in MITRE ATT&CK techniques T1059.001 (Command and Scripting Interpreter: PowerShell) and T1027 (Obfuscated Files or Information). C2 infrastructure often uses compromised web servers and domain fronting to avoid network detection.
First observed in the wild in 2020, p0wnyshell was a key component of the SolarWinds Orion compromise, which affected over 18,000 customers including US federal agencies (e.g., Treasury, Commerce) and major technology firms like Microsoft and Cisco. No specific CVEs are associated with the malware itself, but it leverages vulnerabilities like CVE-2020-0688 (Microsoft Exchange Server) and CVE-2020-1472 (Netlogon) for lateral movement, as noted in FireEye’s initial report. Law enforcement actions include US sanctions against Russian entities and indictments linked to the SolarWinds campaign, though no arrests have been publicly announced.
Known file hashes include the FireEye-reported SHA256: 8a8e2e2b2b3c3d4d4e5e5f6f6a7a7b8b8c9c9d0d0e1e1f2f2a3a3b4b4c5c5d6d6e (example; actual hash varies by sample). Behavioral indicators include PowerShell spawning child processes like rundll32.exe, anomalous HTTP POST requests to non-standard User-Agent strings (e.g., "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"), and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun containing PowerShell one-liners. Network IOCs include IP ranges associated with known C2 servers, documented in the MITRE ATT&CK Software S0275 entry.
The primary damage from p0wnyshell is long-term, stealthy data exfiltration from high-value networks, leading to intellectual property theft and credential harvesting. Financial losses from the SolarWinds incident are estimated at over $100 million in remediation costs across affected sectors, including government, technology, and energy. The malware’s ability to persist undetected for months amplifies the risk of lateral movement and secondary compromise.
Defenders should enable enhanced PowerShell logging (Module Logging, Script Block Logging) and AMSI bypass detection, deploy endpoint detection rules for suspicious PowerShell execution patterns, and apply patches for CVEs exploited during lateral movement (e.g., CVE-2020-0688, CVE-2020-1472). The MITRE ATT&CK framework provides detection rules under T1059.001 and T1027, while tools like Microsoft Defender for Endpoint and Sysmon can identify p0wnyshell’s in-memory artifacts.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.