PowerExchange
S1173 · Windows
PowerExchange is a PowerShell backdoor that has been used by OilRig since at least 2023 including against government targets in the Middle East.
ATT&CK S1173
Sigma rules0
YARA rules0
Live IOCs0