Threats Tagged 'powershell'
View all threats tagged with 'powershell'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'powershell'
Click on any threat for detailed analysis and mitigation recommendations
The domain third-party[.]com, historically used as a documentation placeholder similar to example.com, has been compromised and now serves ClickFix lures to Windows users while displaying harmless content to other operating systems. Since at least June 2026, Windows visitors receive a fake Cloudflare verification page that poisons the clipboard with a malicious PowerShell command, instructing users to press Win+R and paste the payload. The domain appears in over 1,500 files across 1,700+ repositories from trusted sources including Chromium, Sanity, and Vercel. Unlike example.com, third-party[.]com is not IANA-reserved, allowing adversaries to register and weaponize it. The attack leverages social engineering to bypass security tools by using signed Windows binaries, making detection difficult through traditional scanning methods. Join the discussion | AlienVault OTX General | 09/24/2026, 17:09:58 UTC Added: 09/24/2026, 20:02:49 UTC |
North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs. Join the discussion | AlienVault OTX General | 09/24/2026, 12:40:35 UTC Added: 09/24/2026, 19:33:01 UTC |
A sophisticated multi-stage infection chain was discovered through analysis of a system exhibiting frequent PowerShell execution alerts. The attack leveraged multiple layers of obfuscation and concealment techniques, including Registry-based payload storage, DNS TXT record exploitation, and data hidden within image and WAV audio files. The threat actors employed various evasion methods such as security control tampering and in-memory execution to avoid detection. Rather than writing payloads directly to disk, attackers reconstructed malicious code from distributed sources including Registry entries and steganographically encoded data in media files. The ultimate objective of this elaborate infection chain was to deploy cryptocurrency mining operations covertly on compromised systems while maintaining persistent access through multiple redundant mechanisms. Join the discussion | AlienVault OTX General | 09/21/2026, 15:16:13 UTC Added: 09/21/2026, 15:31:54 UTC |
In June 2026, a new malware family named SloppyRAT was identified, likely used by ransomware-related threat actors to establish footholds for lateral movement. Delivered through multi-stage ClickFix infection chains, the malware features encrypted code blocks, EtherHiding for command-and-control resolution via Polygon JSON-RPC protocol, and multiple anti-analysis techniques including junk code and indirect system calls. SloppyRAT implements certificate pinning to prevent TLS traffic inspection and includes 47 built-in PowerShell-like commands for remote access. The infection chain uses finger.exe, IronPython, and deploys CastleLoader and CastleRAT components before installing SloppyRAT. Despite sophisticated capabilities, the codebase contains numerous software bugs affecting persistence mechanisms and other features, suggesting active development. Join the discussion | AlienVault OTX General | 09/10/2026, 17:35:27 UTC Added: 09/11/2026, 09:02:09 UTC |
This threat involves a sophisticated malware infection chain that uses PowerShell loaders to deliver encrypted NetSupport Manager payloads hidden inside fake MP4 files. These MP4 files appear legitimate to basic file-type checks but contain encrypted data in ISO Base Media File Format uuid extension boxes instead of actual video content. The attack starts with PowerShell scripts delivered via Cloudflare-fronted infrastructure, which perform environment checks before retrieving the malicious carrier file. A secondary script extracts and decrypts a large embedded PowerShell payload that silently installs NetSupport Manager, a remote administration tool. The infrastructure includes multiple live endpoints across several autonomous systems, primarily located in Frankfurt and Los Angeles, with command-and-control gateways registered in rapid succession. The attackers use Russian-language business site decoys and frequently rotate carrier files without backward compatibility. Join the discussion | AlienVault OTX General | 08/29/2026, 00:24:24 UTC Added: 08/31/2026, 09:52:14 UTC |
In July 2026, multiple APT campaigns targeted South Korean entities using spear phishing emails with malicious LNK files. Seven distinct attack types employed various techniques such as PowerShell scripts, AutoIt programs, DLL side-loading, and curl.exe downloads. Malware was distributed via platforms like GitHub, Google Drive, and Dropbox, disguised as legitimate documents or resumes. The campaigns deployed backdoors, infostealers, keyloggers, and XenoRAT malware to exfiltrate sensitive information and maintain persistence through Task Scheduler entries. Communication with command and control servers used PubNub channels with Base64-encoded data. The attacks focused on deceiving victims with work-related content to execute malicious payloads. Join the discussion | AlienVault OTX General | 08/28/2026, 10:52:45 UTC Added: 08/28/2026, 16:57:13 UTC |
Kimsuky conducted spear phishing campaigns targeting South Korean and Japanese entities in early 2026. The attacks used LNK malware distributed via OneDrive share links to establish scheduled tasks that periodically retrieved PowerShell scripts from command-and-control servers. These scripts profiled infected systems, exfiltrated email data from Thunderbird and Outlook, and logged keystrokes. The threat actor leveraged legitimate remote control tools such as Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain persistent access. Additionally, a malicious Chrome extension with AI-generated code was used to steal Gmail data. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to hinder tracking efforts. Join the discussion | AlienVault OTX General | 08/20/2026, 17:08:37 UTC Added: 08/20/2026, 23:37:24 UTC |
A threat hunting investigation identified suspicious PowerShell content served from an IP address (203.188.171.166) and domain (dorenzaa.com), both retrieving ZIP archives from Vercel-hosted infrastructure. The PowerShell loaders extract and execute payloads locally, including Grape.exe, UltraToolliteSetup.exe, and draw.io.exe. Analysis revealed heavily obfuscated PowerShell stages utilizing Base64 encoding, XOR-based obfuscation with the key 'Write', dynamically constructed IEX commands, and hidden PowerShell execution. A decoy 'Verification complete!' message disguised as Google.com was presented to victims during execution. Multiple Vercel instances hosted additional artifacts including loader scripts and executables. The initial infection vector remains unidentified, suggesting these PowerShell-hosting URLs represent second-stage delivery points in a multi-stage attack chain. Join the discussion | AlienVault OTX General | 08/10/2026, 14:20:36 UTC Added: 08/10/2026, 15:56:14 UTC |
The Kimsuky threat group has integrated artificial intelligence capabilities into its attack operations, establishing local large language model environments using Ollama, GPT4All, and Msty. Evidence indicates the group is accumulating technologies to incorporate AI across attack operations, including AI-generated decoy documents and retrieval-augmented generation for document analysis. The campaign, dubbed Operation GitPower, continues targeting foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks utilize malicious LNK files contained in ZIP archives, executing obfuscated PowerShell scripts that abuse Git-based repositories as command-and-control infrastructure. The group distributes encrypted AsyncRAT payloads disguised as image files through GitHub. Linguistic indicators including North Korean vocabulary patterns such as "싸이트", "가입리력", and "로출되였는지" support attribution to North Korean state-sponsored operations under the Reconnaissance General Bureau. Join the discussion | AlienVault OTX General | 08/10/2026, 13:45:54 UTC Added: 08/10/2026, 15:56:14 UTC |
Since January 2026, a threat actor likely functioning as an initial access broker for ransomware operations has been targeting organizations through Microsoft Teams vishing attacks. Attackers impersonate IT helpdesk staff to convince victims to initiate Quick Assist remote sessions. Following initial compromise, PowerShell scripts deploy a Go-based backdoor called GoGRPC, which exists in four distinct variants: Lep, Giver, Pet, and Kind. These variants communicate with command-and-control infrastructure using gRPC over HTTP/2, an uncommon approach that helps blend malicious traffic with legitimate communications. Additional tools observed include BlindDoor backdoor, RevSocket and PyGRPC SOCKS proxies, S3Siphon data exfiltration utility, and RSOX Rust-based proxy relay. Recent campaigns show increased sophistication and selectivity, with heightened focus on corporate environments through enhanced PowerShell scripts capable of antivirus detection, domain controller fingerprinting, and system reconnaissance b... Join the discussion | AlienVault OTX General | 07/27/2026, 16:45:15 UTC Added: 07/28/2026, 10:22:27 UTC |
Showing 1 to 10 of 96 results