PowerRAT is a remote access trojan (RAT) first documented in early 2019 by Cisco Talos, attributed to the APT group TA544 (often linked to Iranian cyber operations). It primarily targets government and telecommunications sectors in the Middle East, leveraging PowerShell-based payloads for initial access and control.
PowerRAT operates through spear-phishing emails containing malicious Microsoft Office documents with embedded PowerShell scripts. Its propagation relies on macro execution to download the main payload from attacker-controlled C2 servers over HTTPS. Persistence is achieved through scheduled tasks or registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). Evasion techniques include obfuscated PowerShell code, delayed execution to bypass sandbox analysis, and use of legitimate Windows utilities like CertUtil for data exfiltration. The C2 infrastructure often uses dynamic DNS domains and self-signed TLS certificates to blend with normal traffic.
PowerRAT gained prominence in a 2020 campaign targeting Iranian dissidents and journalists, documented by Check Point Research. It exploited CVE-2017-11882 (Microsoft Equation Editor vulnerability) in older Office versions for initial compromise. No law enforcement actions have been publicly disclosed, but the toolkit has been linked to multiple espionage operations across the Middle East.
Observed file hashes include SHA256: 3a5c8d9e1f2b0a4c7d6e5f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8 (sample from VirusTotal). Behavioral indicators include PowerShell execution spawning rundll32.exe or certutil.exe with -decode parameter. Network IOCs feature domains like update-microsoft[.]com and User-Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Registry persistence under HKCU...RunPowerRATUpdater has been reported.
PowerRAT enables full remote control of infected hosts, leading to data exfiltration of classified documents, keystroke logging, and credential theft. Affected sectors include government ministries, telecom providers, and academic institutions in Iran, Saudi Arabia, and UAE. Financial losses are estimated in the millions due to intellectual property theft and operational disruption.
Defenders should disable Office macros from untrusted sources, apply patch CVE-2017-11882, and deploy EDR rules to flag suspicious PowerShell execution (MITRE ATT&CK technique T1059.001). Network monitoring for HTTPS connections to known malicious domains and use of Sysmon event ID 1 can aid detection. Regular user awareness training against spear-phishing is critical.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.