Skip to content

Malware

POWERPLANT

This powershell code is a PowerShell written backdoor used by FIN7.

POWERPLANT is a PowerShell malware family operated by FIN7.

Background

POWERPLANT is a backdoor coded in PowerShell and employed by FIN7. According to Mandiant, it turned out to be a "vast backdoor framework with a breadth of capabilities, depending on which modules are delivered from the C2 server."


Source: Malpedia (Fraunhofer FKIE).