logo

Charming Kitten Updates POWERSTAR with an InterPlanetary Twist

ID: 62a9a31b-0024-543e-8198-f9e4eca70361

STIX ID: report--62a9a31b-0024-543e-8198-f9e4eca70361

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2023-06-28

Date Updated: 2026-05-01

...
...

Volexity describes Charming Kitten's targeted spear-phishing operations and a new, more sophisticated variant of their POWERSTAR backdoor: the malware uses staged in-memory PowerShell execution, remotely-hosted decryption routines (Backblaze/IPFS), dynamic AES-based C2 comms, and modular capabilities (reconnaissance, persistence, cleanup, file crawling). The report includes a timeline of distribution methods, module analysis (including an expanded cleanup module and an IPFS variant), indicators, and detection guidance (YARA, IOCs, IPFS provider blocking).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.