Malware

New PowerDrop malware targets U.S. aerospace industry

0

A new PowerShell based malware script named PowerDrop was found to be used in attacks targeting the U.S. aerospace defense industry.

The PowerDrop malware was discovered by Adlumin, and a sample of the malware was found in the network of a defense contractor in the U.S last month.

The name is derived from the tool, Windows PowerShell, used to concoct the script, and ‘Drop’ from the DROP (DRP) string used in the code for padding.

PowerDrop uses PowerShell and WMI (Windows Management Instrumentation) to create a persistent remote access Trojan (RAT) on the breached networks.

Adlumin identified PowerDrop using machine learning detection that scrutinizes PowerShell script execution content. The infection chain or initial compromise is unknown.

According to the analysts, the attackers might have deployed the script using an exploit, phishing emails to targets, or spoofed software download sites.

By looking at the system logs, the researchers discovered that the malicious script was executed using previously registered WMI event filters and consumers named ‘SystemPowerManager,’ created by the malware upon system compromise using the ‘wmic.exe’ command-line tool.

PowerDrop is also a post-exploitation tool, and is designed to gather information from victim networks after obtaining initial access through other means.

The malware employs Internet Control Message Protocol (ICMP) echo request messages as beacons to initiate communications with a command-and-control (C2) server.

The server responds back with an encrypted command which is decoded and run on the compromised host. A similar ICMP ping message is used for exfiltrating the results of the instruction.

Organizations, particularly those in the aerospace defense industry, must be vigilant for this threat, monitor PowerShell execution and look for unusual WMI activity.

Image Credits : SSC Srl

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

British Airways, BBC and Boots hit by Zellis data breach

Previous article

FBI warns of rise in Deepfake Sextortion schemes

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *