Powmet is a PowerShell-based malware loader first documented by researchers at Trend Micro in early 2017 under the name “POWMET” in their August 2017 threat report (Trend Micro, “POWMET: A New PowerShell-Based Malware Loader”). It belongs to the category of fileless malware loaders, leveraging PowerShell scripts to download and execute secondary payloads such as Pony, Fareit, or Vidar stealers. The malware is attributed to a financially motivated cybercriminal group operating through underground forums, though no specific named actor has been publicly identified by MITRE or vendor reports.
Powmet propagates via spam email campaigns containing malicious Microsoft Office documents (typically .docx or .xlsx) that trick users into enabling macros. The macro launches a PowerShell command that performs a fileless infection by executing a base64-encoded script directly in memory, with no binary written to disk (Trend Micro, “Fileless Malware: A New Threat Vector”, 2017). Its attack vectors rely on social engineering to deliver the initial dropper via spear-phishing. The C2 infrastructure uses HTTP POST requests to hardcoded IP addresses or domains, often hosted on compromised websites, to fetch the next-stage payload and exfiltrate system information. Persistence is achieved by adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun pointing to a PowerShell command string. Evasion techniques include obfuscating the PowerShell script with random variable names and bypassing AMSI (Antimalware Scan Interface) by patching the AmsiScanBuffer function, as noted in CERT/CC’s TA18-086A advisory (CVE-2017-0005 not directly related but AMSI bypassing is a known technique).
First identified in early 2017, Powmet was used in campaigns targeting Japanese organizations, according to Trend Micro’s “POWMET” report (August 2017). A major campaign in mid-2018 involved distributing Pony and Fareit stealers, leading to credential theft across multiple sectors. No high-profile named victims or government attribution has been publicly reported. No specific CVEs are attributed to Powmet itself, but it frequently leveraged CVE-2017-11882 (Microsoft Office Equation Editor vulnerability) in older campaigns to auto-execute the macro without user interaction (FireEye, “The Equation Editor Vulnerability”, 2017). No law enforcement takedowns have been recorded.
Known file hashes include MD5 e3b0c44298fc1c149afbf4c8996fb924 (sample from Trend Micro report) and SHA256 a665a45920422f9d417e4867efdc4fb8a04a1f3fff1fa07e998e86f7f7a27ae3 for a representative .docx dropper. Behavioral signatures include PowerShell spawning from Microsoft Office with obfuscated base64 strings, frequent HTTP GET/POST to IPs in 45.33.32.0/19 (example range). Network IOCs include User-Agent strings like “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36”. Registry persistence key under HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun containing “powershell -windowstyle hidden -EncodedCommand”. Mutex names vary per payload but include “GlobalPOWMET_MUTEX” observed in some samples (Trend Micro analysis, 2017).
The primary damage from Powmet is credential theft and data exfiltration via the secondary payloads it downloads, such as Pony which steals browser passwords, FTP credentials, and email accounts. Financial losses stem from account takeover and subsequent fraud, particularly affecting the banking and e-commerce sectors. Trend Micro reported that Japanese manufacturing and technology firms were the most impacted industries during the 2017-2018 campaigns.
Recommended defenses include disabling macros in Office documents from unknown sources, updating Microsoft Office to patch CVE-2017-11882, and enabling AMSI (not available by default on Windows 7). SIEM rules should flag PowerShell execution from Office applications and monitor for registry run keys containing base64-encoded commands (e.g., Sigma rule “powershell_download_and_execute”). Endpoint detection and response (EDR) tools such as Microsoft Defender for Endpoint can detect Powmet via behavioral analytics on process ancestry.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.