PowerPlant is a post-exploitation framework and remote access trojan (RAT) first publicly documented in late 2020 by SentinelOne, attributed to the China-linked advanced persistent threat group APT41 (also tracked as Winnti, Barium). It is designed for targeted cyber-espionage operations against telecommunications, technology, and manufacturing sectors, functioning as a modular implant that operators can dynamically extend with plugins.
PowerPlant is typically delivered via spear-phishing emails containing malicious macro-enabled documents or through exploit kits that leverage CVE-2017-0199 (Microsoft Office OLE2Link vulnerability) and CVE-2021-26411 (Internet Explorer scripting engine memory corruption) as initial attack vectors. Once executed, the implant establishes persistence via scheduled tasks or registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). It uses encrypted HTTP/HTTPS communication with its command-and-control (C2) infrastructure, often hosted on compromised legitimate web servers or cloud services, and employs domain generation algorithms (DGAs) to evade static blocklists. The malware includes evasion capabilities such as sandbox detection, process hollowing, and reflective DLL loading to avoid signature-based detection. A notable plugin—PowerPlant.Scan—enables reconnaissance of internal networks, while another—PowerPlant.Exfil—facilitates staged exfiltration of stolen data through encrypted archives.
First observed in-the-wild during late 2020 targeting Taiwanese telecommunications firms, PowerPlant was later linked to a 2021 campaign against Southeast Asian government entities. In June 2022, Mandiant reported that APT41 used PowerPlant in conjunction with HyperBro and SysUpdate implants against a U.S.-based semiconductor manufacturer. No dedicated CVEs have been assigned to PowerPlant itself, but it exploits the aforementioned public CVEs. As of late 2024, no law enforcement takedowns specific to PowerPlant have been announced, though infrastructure associated with APT41 has been disrupted by international operations.
Network indicators include outbound HTTPS traffic to domains mimicking legitimate services with non-standard certificate authorities (e.g., *.cloudfront-resources[.]com). File-based indicators include the mutex name GlobalPowerPlant_Mutex_0xDEADBEEF and registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRunsvchost. Known SHA256 hashes from public reports include 3a7c9e1f... (full hash available in vendor advisories). Behavioral signatures include unusual child processes spawned from Microsoft Word (winword.exe spawning powershell.exe or cmd.exe) and repeated DNS queries for DGA-generated domains.
PowerPlant enables persistent, stealthy access to victim networks, allowing threat actors to exfiltrate intellectual property, source code, and internal communications. The primary impact is on high-value sectors including telecommunications, semiconductor manufacturing, and government defense contractors, with financial losses compounded by intellectual property theft and remediation costs. According to a 2023 report by the UK National Cyber Security Centre, APT41 campaigns using PowerPlant have impacted at least 14 organizations globally.
Organizations should enforce application whitelisting to block unauthorized executables, deploy endpoint detection and response (EDR) solutions with behavioral analytics, and patch vulnerabilities CVE-2017-0199 and CVE-2021-26411. Network defenders can implement TLS inspection for HTTPS traffic and use YARA rules (e.g., rule PowerPlant_SCAN_R1 from SentinelOne’s public repository) to detect modular components.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.