Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'powershell'

View all threats tagged with 'powershell'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: powershell

Threats Tagged 'powershell'

Click on any threat for detailed analysis and mitigation recommendations

Investigating a Multi-Stage PowerShell Loader
0

A multi-stage PowerShell loader campaign was identified involving heavily obfuscated PowerShell scripts hosted on Vercel infrastructure. The loaders retrieve and execute payloads such as Grape.exe, UltraToolliteSetup.exe, and draw.io.exe. Obfuscation techniques include Base64 encoding, XOR with the key 'Write', and dynamic IEX command construction. Victims see a decoy 'Verification complete!' message disguised as Google.com during execution. The initial infection vector is unknown, indicating these URLs serve as second-stage delivery points in the attack chain.

Join the discussion
Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
0

The Kimsuky threat group has incorporated artificial intelligence into its attack operations, using local large language models such as Ollama, GPT4All, and Msty. Their campaign, named Operation GitPower, targets foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks involve spear phishing with malicious LNK files in ZIP archives that execute obfuscated PowerShell scripts. The group abuses Git-based repositories for command-and-control infrastructure and distributes encrypted AsyncRAT payloads disguised as image files via GitHub. Linguistic evidence links these operations to North Korean state-sponsored actors under the Reconnaissance General Bureau.

Join the discussion
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
0

Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b...

Join the discussion
June 2026 Threat Trend Report on APT Attacks (South Korea)
0

AhnLab monitored Advanced Persistent Threat attacks targeting South Korea during June 2026, identifying multiple attack types distributed primarily through spear phishing campaigns. Threat actors disguised malicious files as work-related documents, with LNK files being the most common delivery method. Six distinct attack types were observed, employing various techniques including malicious PowerShell commands, AutoIt malware, curl.exe abuse, GitHub repository exploitation, Task Scheduler persistence, DLL side-loading, and Python backdoors. These attacks deployed Infostealers, keyloggers, backdoors, and remote access tools like XenoRAT. Once executed, the malware established persistence, exfiltrated system information, and enabled remote control of compromised systems. Organizations are advised to verify email senders, avoid opening files from unknown sources, apply security patches, and maintain updated antivirus software to mitigate these persistent threats.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: powershell
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses