s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.powerplant

📛 Threat Title

Malware family: POWERPLANT

Category: POWERPLANT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.powerplant`. Printable name: POWERPLANT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.powerplant VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerplant

IOC database

Type
domain
Value
ps1.powerplant
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.powerplant

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerplant

References (1)

Remediations (9)

  • web:cloud.google.com

    FIN7's initial access techniques have diversified to include software supply chain compromise and the use of stolen credentials, in addition to their traditional phishing techniques. We also observed FIN7 use POWERPLANT as their first stage malware instead of LOADOUT and/or GRIFFON in newer intrusions.

  • web:conferences.iaea.org

    We then identify key trends in malware capabilities and outline the impact of these trends on nuclear power plants, their operators, and industrial system manufacturers. Over the past 10 years, we have seen a remarkable change in malware sophistication and the adoption of new strategies by malware authors.

  • web:en.wikipedia.org

    Stuxnet is a malicious computer worm first uncovered on 17 June 2010 [2] and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the Iran nuclear program after it was first installed on a computer at the Natanz Nuclear Facility in 2009. [3][4 ...

  • web:malpedia.caad.fkie.fraunhofer.de

    ps1. powerplant (Back to overview) POWERPLANT Propose Change Actor (s): FIN7 This powershell code is a PowerShell written backdoor used by FIN7. Regarding to Mandiant that is was revealed to be a "vast backdoor framework with a breadth of capabilities, depending on which modules are delivered from the C2 server."

  • web:windowsforum.com

    The emergence of RESURGE signals more than just another entry in a long line of malware threats. According to CISA, RESURGE contains advanced persistence features inherited from the SPAWNCHIMERA malware family—a group notorious for its ability to survive system reboots and avoid simplistic remediation .

  • web:www.bleepingcomputer.com

    A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed "MiniPlasma" that lets attackers gain SYSTEM privileges on fully patched ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.fortra.com

    According to Google's Mandiant M-Trends 2025 Report, BEACON remains the most frequently observed malware family worldwide for the fifth year running. The report also gives credit to Operation MORPHEUS, which resulted in an 80% reduction of the unauthorized (or illicit) copies of Cobalt Strike over the past two years.

  • web:www.ncsc.gov.uk

    How to defend organisations against malware or ransomware attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.