Skip to content

Malware

PowerHarbor

PowerHarbor is a modular PowerShell-based malware that consists of various modules.

PowerHarbor is a PowerShell malware family.

Background

PowerHarbor is a modular PowerShell-based threat composed of several distinct modules. Its main module keeps in continuous contact with the C2 server, running and then removing the extra modules it receives. C2 communication is presently encrypted with RSA using hardcoded key material, and the main module also includes virtual machine (VM) detection. Built around the Invoke-Stealer function, the StealData module steals system information, browser-saved credentials, cryptocurrency wallet data, and credentials from applications such as Telegram, FileZilla, and WinSCP.


Source: Malpedia (Fraunhofer FKIE).