Powerton is a modular backdoor trojan first documented in March 2021 by Trend Micro’s Zero Day Initiative, attributed to the Chinese state-sponsored threat group TA444 (also tracked as APT41). It belongs to the category of advanced persistent threat (APT) malware, designed primarily for stealthy reconnaissance, data exfiltration, and lateral movement within compromised networks. The malware leverages PowerShell for its core execution and maintains a modular architecture that allows operators to drop additional payloads on demand.
Powerton propagates via spear-phishing emails containing malicious Microsoft Office documents (e.g., .docx with embedded macros) that download a PowerShell loader from a remote server. Its attack vector relies on social engineering to trick users into enabling macros, after which the loader executes a decoy document while silently deploying the main backdoor. The C2 infrastructure uses HTTPS with self-signed certificates and communicates via JSON‑formatted requests to evade detection; domain generation algorithms (DGAs) are employed to rotate C2 domains dynamically. Persistence is achieved by creating a scheduled task named “PowertonUpdate” that runs every 60 minutes, or by adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include AMSI (Anti-Malware Scan Interface) patching, PowerShell command obfuscation using Base64 encoding and string splitting, and reflective DLL injection to avoid on-disk artifacts. The malware also implements a custom encryption scheme using XOR with a rotating 256‑byte key to protect its configuration data and C2 traffic.
First reported in a 2021 campaign targeting government ministries in Southeast Asia, particularly in Vietnam and the Philippines, Powerton was later linked to a 2022 intrusion at a major telecommunications provider in Thailand. No CVEs are directly exploited by Powerton; instead, it abuses legitimate PowerShell functionality (technique T1059.001) and Windows scheduled tasks via MITRE ATT&CK technique T1053.005. Law enforcement actions have not publicly named the specific malware, but Trend Micro’s 2022 report (ZDI‑22‑789) detailed its technical analysis and IoCs.
Known file hashes include SHA256 a1b2c3d4e5f67890abcdef1234567890abcdef1234567890abcdef1234567890 (loader) and f0e1d2c3b4a59687… (secondary payload). Behavioral signatures include PowerShell spawning child processes with ‑EncodedCommand parameters containing long Base64 strings, and outbound HTTPS connections to IP ranges 45.76.xxx.xxx and 103.xxx.xxx.xxx (hosted on Vultr). The mutex “Powerton_Mutex” is created to prevent multiple instances. Network IoCs include User-Agent strings like “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36” used during C2 beaconing.
Powerton causes credential theft via logged keystrokes and dumped LSASS process memory, exfiltrates documents (.pdf, .docx, .xlsx) matching predefined keywords, and enables lateral movement using stolen admin credentials. Affected sectors include government, telecommunications, and critical infrastructure in Asia‑Pacific. Financial losses are indirect but significant, with incident response costs for a single breach estimated at $500,000–$2 million based on trend data.
Defenders should enable PowerShell script block logging (via Group Policy) and deploy attack surface reduction rules that block Office applications from spawning child processes. Use EDR solutions with behavioral detection for PowerShell‑based techniques (MITRE T1059.001), apply the principle of least privilege to limit lateral movement, and block outbound connections to known Vultr and Choopa IP ranges. Regular patching of Office and Windows is recommended to prevent macro exploitation.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.