POWERSOURCE

POWERSOURCE is a PowerShell backdoor that is a heavily obfuscated and modified version of the publicly available tool DNS_TXT_Pwnage. It was observed in February 2017 in spearphishing campaigns against personnel involved with United States Securities and Exchange Commission (SEC) filings at various organizations. The malware was delivered when macros were enabled by the victim and a VBS script was dropped. [1] [2]

ID: S0145
Associated Software: DNSMessenger

Type: MALWARE
Platforms: Windows

Version: 1.0

Associated Software Descriptions

NameDescription
DNSMessengerBased on similar descriptions of functionality, it appears S0145, as named by FireEye, is the same as the first stages of a backdoor named DNSMessenger by Cisco's Talos Intelligence Group. However, FireEye appears to break DNSMessenger into two parts: S0145 and S0146. [2] [1]

Techniques Used

DomainIDNameUse
EnterpriseT1096NTFS File AttributesIf the victim is using PowerShell 3.0 or later, POWERSOURCE writes its decoded payload to an alternate data stream (ADS) named kernel32.dll that is saved in %PROGRAMDATA%\Windows\.[2]
EnterpriseT1086PowerShellPOWERSOURCE is a PowerShell backdoor.[1][2]
EnterpriseT1012Query RegistryPOWERSOURCE queries Registry keys in preparation for setting Run keys to achieve persistence.[2]
EnterpriseT1060Registry Run Keys / Startup FolderPOWERSOURCE achieves persistence by setting a Registry Run key, with the path depending on whether the victim account has user or administrator access.[2]
EnterpriseT1105Remote File CopyPOWERSOURCE has been observed being used to download TEXTMATE and the Cobalt Strike Beacon payload onto victims.[1]
EnterpriseT1071Standard Application Layer ProtocolPOWERSOURCE uses DNS TXT records for C2.[1][2]

Groups

Groups that use this software:

FIN7

References