POWERTON
S0371 · Windows
POWERTON is a custom PowerShell backdoor first observed in 2018. It has typically been deployed as a late-stage backdoor by APT33. At least two variants of the backdoor have been identified, with the later version containing improved functionality.
ATT&CK S0371
Sigma rules0
YARA rules0
Live IOCs0