Skip to content

Malware

POWERTRASH

This PowerShell written malware is an in-memory dropper used by FIN7 to execute the included/embedded payload.

POWERTRASH is a PowerShell malware family operated by FIN7.

Background

This PowerShell-based malware acts as an in-memory dropper that FIN7 uses to run its bundled/embedded payload. As Mandiant's blog post puts it: "POWERTRASH is a uniquely obfuscated iteration of a shellcode invoker included in the PowerSploit framework available on GitHub."


Source: Malpedia (Fraunhofer FKIE).