s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.powerstar

📛 Threat Title

Malware family: POWERSTAR

Category: POWERSTAR First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.powerstar`. Printable name: POWERSTAR.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.powerstar VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerstar

IOC database

Type
domain
Value
ps1.powerstar
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.powerstar

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerstar

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    Despite these developments, Charming Kitten's overall strategy and use of POWERSTAR remain consistent, with the malware showing a refined cleanup module and broader persistence mechanisms, reflecting the group's ongoing commitment to espionage activities and avoiding detection.

  • web:heimdalsecurity.com

    Cybersecurity researchers recently published an advisory on the evolution of POWERSTAR backdoor malware and advanced spear-phishing techniques used by Charming Kitten, a threat actor believed to be from Iran. The most recent version of POWERSTAR has improved operational security measures, making it more difficult to analyze and gather intelligence on this malware .

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the POWERSTAR malware family including references, samples and yara signatures.

  • web:securityaffairs.com

    The Charming Kitten APT group expanded the cleanup module, which is used to erase all traces of the infection. "Since Volexity first observed POWERSTAR in 2021, Charming Kitten has reworked the malware to make detection more difficult. The most significant change is the downloading of the decryption function from remotely hosted files.

  • web:thehackernews.com

    Charming Kitten, the nation-state actor affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC), has been attributed to a bespoke spear-phishing campaign that delivers an updated version of a fully-featured PowerShell backdoor called POWERSTAR . "There have been improved operational security measures placed in the malware to make it more difficult to analyze and collect intelligence ...

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.enigmasoftware.com

    POWERSTAR Backdoor Infection Vectors are Evolving In the May 2023 attack campaign, the Charming Kitten employed a clever strategy to enhance the effectiveness of the POWERSTAR malware . To mitigate the risk of exposing their bad code to analysis and detection, they implemented a two-step process.

  • web:www.infosecurity-magazine.com

    Charming Kitten, a threat actor believed to operate from Iran, has been found to be evolving its PowerStar backdoor malware alongside sophisticated spear-phishing techniques. Cybersecurity firm Volexity discussed the findings in an advisory published on Wednesday, where it said the new version of ...

  • web:www.redpacketsecurity.com

    Charming Kitten, the nation-state actor affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC), has been attributed to a bespoke spear-phishing campaign that delivers an updated version of a fully-featured PowerShell backdoor called POWERSTAR . "There have been improved operational security measures placed in the malware to make it more difficult to analyze and collect intelligence ...

  • web:www.volexity.com

    In an effort to see how the malware has evolved, Volexity reviewed historic activity related to POWERSTAR since Volexity first encountered it in 2021. Various security companies have also encountered POWERSTAR , and Charming Kitten has been observed distributing POWERSTAR in a surprising number of different ways, as described in the timeline below.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.