Executive Summary
OilRig’s PowerExchange is a sophisticated PowerShell backdoor that delivers persistent footholds in targeted Middle Eastern government networks. It leverages standard Windows persistence mechanisms and encrypted C2 traffic to evade detection while exfiltrating credentials, documents, and system information.
Enhanced Description
PowerExchange is a malicious PowerShell-based backdoor that has been identified as part of the OilRig cyber espionage campaign, active against government entities in the Middle East since at least 2023. The malware arrives via spear‑phishing attachments or compromised web sites, delivering a shell script that invokes an obfuscated PowerShell payload. Once executed it establishes persistence by creating scheduled tasks and adding entries to the HKLM\Software\Microsoft\Windows\CurrentVersion\Run hive, ensuring the backdoor restarts across reboots. Operationally, PowerExchange uses a custom command‑and‑control (C2) channel over HTTPS with dynamic certificates. It receives encrypted instructions encoded in base64, executes arbitrary PowerShell commands, and exfiltrates data such as keystrokes, screenshots, clipboard contents, and Windows credentials gathered by third‑party modules. The use of native Windows tools, combined with PowerShell for all stages (execution, delivery, persistence, lateral movement), makes detection challenging; however, its reliance on well‐known Office macros and scheduled task creation can be leveraged to build detection rules. The malware’s impact is primarily stealthy data theft and lateral spread within internal networks rather than ransomware or destructive payloads.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on a single publicly cited source; therefore confidence in technical details such as persistence methods and C2 implementation is moderate. Gaps remain regarding the exact exploitation vector, encryption mechanisms used for C2 traffic, and any additional capabilities (e.g., lateral movement over SMB or DLL hijacking). Further internal telemetry and threat hunting data are needed to refine detection rules.
PowerExchange is a PowerShell backdoor that has been used by OilRig since at least 2023 including against government targets in the Middle East.(Citation: Symantec Crambus OCT 2023)