s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.powershower

📛 Threat Title

Malware family: PowerShower

Category: PowerShower First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.powershower`. Printable name: PowerShower.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.powershower VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powershower

IOC database

Type
domain
Value
ps1.powershower
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.powershower

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ps1.powershower

References (1)

Remediations (10)

  • web:advisory.eventussecurity.com

    By blending legacy exploits with updated malware like VBShower, PowerShower , and VBCloud, the group has created a resilient ecosystem capable of sustained espionage. Their focus remains consistent—governmental and strategic sectors—suggesting motives aligned with intelligence gathering rather than financial gain.

  • web:attack.mitre.org

    PowerShower has added a registry key so future powershell.exe instances are spawned off-screen by default, and has removed all registry entries that are left behind during the dropper process.

  • web:cybersecsentinel.com

    The group has recently integrated the VBCloud backdoor into its arsenal, supplementing its well-documented VBShower and PowerShower malware . This new tool uses public cloud services for command-and-control (C2) infrastructure, enhancing its operational stealth and adaptability.

  • web:gbhackers.com

    Malware execution flow. VBShower then orchestrates the deployment of three additional backdoors: PowerShower , VBCloud, and CloudAtlas. This modular approach provides flexibility and redundancy in maintaining persistent access.

  • web:hivepro.com

    Attack: The cyber threat group Cloud Atlas unveiled a sophisticated, previously unknown toolset, targeting victims with phishing emails that exploit a known vulnerability. This clever attack chain drops malicious files, including the VBShower and PowerShower backdoors, allowing attackers to stealthily infiltrate systems. Cloud Atlas continues to evolve its methods to remain under the radar.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the PowerShower malware family including references, samples and yara signatures.

  • web:openhunting.io

    Opensource Threat Hunting & Intelligence (Palo Alto) POWERSHOWER acts as an initial reconnaissance foothold and is almost certainly used to download and execute a secondary payload with a more complete set of features. By only using this simple backdoor to establish a foothold, the attacker can hold back their most sophisticated and complex malware for later stages, making them less likely to ...

  • web:securelist.com

    We analyze the latest activity by the Cloud Atlas gang. The attacks employ the PowerShower , VBShower and VBCloud modules to download victims' data with various PowerShell scripts.

  • web:support.trellix.com

    The campaign takes advantage of flaws in Microsoft Word in an attempt to drop a PowerShell backdoor labeled " POWERSHOWER " onto the infected system. The malware steals sensitive information from a compromised system and uploads it to a command and control server under the attackers control.

  • web:thehackernews.com

    Explore the latest news, real-world incidents, expert analysis, and trends in PowerShower — only on The Hacker News, the leading cybersecurity and IT news platform.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.