Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware PowerExchange

PowerExchange

TLP:CLEAR
Family

AI Analysis

· 3 hours ago

Executive Summary

OilRig’s PowerExchange is a sophisticated PowerShell backdoor that delivers persistent footholds in targeted Middle Eastern government networks. It leverages standard Windows persistence mechanisms and encrypted C2 traffic to evade detection while exfiltrating credentials, documents, and system information.

Enhanced Description

PowerExchange is a malicious PowerShell-based backdoor that has been identified as part of the OilRig cyber espionage campaign, active against government entities in the Middle East since at least 2023. The malware arrives via spear‑phishing attachments or compromised web sites, delivering a shell script that invokes an obfuscated PowerShell payload. Once executed it establishes persistence by creating scheduled tasks and adding entries to the HKLM\Software\Microsoft\Windows\CurrentVersion\Run hive, ensuring the backdoor restarts across reboots. Operationally, PowerExchange uses a custom command‑and‑control (C2) channel over HTTPS with dynamic certificates. It receives encrypted instructions encoded in base64, executes arbitrary PowerShell commands, and exfiltrates data such as keystrokes, screenshots, clipboard contents, and Windows credentials gathered by third‑party modules. The use of native Windows tools, combined with PowerShell for all stages (execution, delivery, persistence, lateral movement), makes detection challenging; however, its reliance on well‐known Office macros and scheduled task creation can be leveraged to build detection rules. The malware’s impact is primarily stealthy data theft and lateral spread within internal networks rather than ransomware or destructive payloads.

Key Capabilities

  • Obfuscated PowerShell execution
  • Creates scheduled tasks and registry Run keys for persistence
  • Establishes HTTPS-based command‑and‑control with dynamic certificates
  • Decodes base64‑encoded instructions and executes arbitrary PowerShell commands
  • Exfiltrates sensitive data including screenshots, clipboard, keystrokes, and credentials

ATT&CK Techniques

T1059.001
T1060
T1053.002
T1041
T1570
T1557

Recommended Actions

  • Enable Windows PowerShell script block logging and transcription to capture payload activity
  • Implement AppLocker or Software Restriction Policies to block untrusted executables and restrict PowerShell scripts based on signatures
  • Continuously monitor for new scheduled tasks and changes to the HKLM\Software\Microsoft\Windows\CurrentVersion\Run hive
  • Deploy network monitoring rules that flag unexplained outbound HTTPS traffic from legitimate processes to unknown domains
  • Maintain up‑to‑date endpoint protection with behavior analytics focused on PowerShell reconnaissance

Suggested Tags

OilRig
PowerShell backdoor
Command and Control
Espionage
Government targets
Middle East
Cyber espionage
Persistent malware
Credential theft

Confidence Assessment

The analysis is based on a single publicly cited source; therefore confidence in technical details such as persistence methods and C2 implementation is moderate. Gaps remain regarding the exact exploitation vector, encryption mechanisms used for C2 traffic, and any additional capabilities (e.g., lateral movement over SMB or DLL hijacking). Further internal telemetry and threat hunting data are needed to refine detection rules.

Description

PowerExchange is a PowerShell backdoor that has been used by OilRig since at least 2023 including against government targets in the Middle East.(Citation: Symantec Crambus OCT 2023)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.