RaqibCTI
malware

POWERTON

S0371 · ATT&CK v19.2
Platforms
Windows
Tracked actors
1

View on attack.mitre.org ↗

Description

[POWERTON](https://attack.mitre.org/software/S0371) is a custom PowerShell backdoor first observed in 2018. It has typically been deployed as a late-stage backdoor by [APT33](https://attack.mitre.org/groups/G0064). At least two variants of the backdoor have been identified, with the later version containing improved functionality.(Citation: FireEye APT33 Guardrail)

Actors that use this

1 tracked actor
APT33ATT&CK-attributed