TF-MAL-ps1.powerstar
📛 Threat Title
Malware family: POWERSTAR
Description
ThreatFox malware family `ps1.powerstar`. Printable name: POWERSTAR.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ps1.powerstar
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerstar
IOC database
- Type
- domain
- Value
ps1.powerstar- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ps1.powerstar
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powerstar
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Despite these developments, Charming Kitten's overall strategy and use of POWERSTAR remain consistent, with the malware showing a refined cleanup module and broader persistence mechanisms, reflecting the group's ongoing commitment to espionage activities and avoiding detection.
-
web:heimdalsecurity.com
Cybersecurity researchers recently published an advisory on the evolution of POWERSTAR backdoor malware and advanced spear-phishing techniques used by Charming Kitten, a threat actor believed to be from Iran. The most recent version of POWERSTAR has improved operational security measures, making it more difficult to analyze and gather intelligence on this malware .
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the POWERSTAR malware family including references, samples and yara signatures.
-
web:securityaffairs.com
The Charming Kitten APT group expanded the cleanup module, which is used to erase all traces of the infection. "Since Volexity first observed POWERSTAR in 2021, Charming Kitten has reworked the malware to make detection more difficult. The most significant change is the downloading of the decryption function from remotely hosted files.
-
web:thehackernews.com
Charming Kitten, the nation-state actor affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC), has been attributed to a bespoke spear-phishing campaign that delivers an updated version of a fully-featured PowerShell backdoor called POWERSTAR . "There have been improved operational security measures placed in the malware to make it more difficult to analyze and collect intelligence ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.enigmasoftware.com
POWERSTAR Backdoor Infection Vectors are Evolving In the May 2023 attack campaign, the Charming Kitten employed a clever strategy to enhance the effectiveness of the POWERSTAR malware . To mitigate the risk of exposing their bad code to analysis and detection, they implemented a two-step process.
-
web:www.infosecurity-magazine.com
Charming Kitten, a threat actor believed to operate from Iran, has been found to be evolving its PowerStar backdoor malware alongside sophisticated spear-phishing techniques. Cybersecurity firm Volexity discussed the findings in an advisory published on Wednesday, where it said the new version of ...
-
web:www.redpacketsecurity.com
Charming Kitten, the nation-state actor affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC), has been attributed to a bespoke spear-phishing campaign that delivers an updated version of a fully-featured PowerShell backdoor called POWERSTAR . "There have been improved operational security measures placed in the malware to make it more difficult to analyze and collect intelligence ...
-
web:www.volexity.com
In an effort to see how the malware has evolved, Volexity reviewed historic activity related to POWERSTAR since Volexity first encountered it in 2021. Various security companies have also encountered POWERSTAR , and Charming Kitten has been observed distributing POWERSTAR in a surprising number of different ways, as described in the timeline below.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.