logo

Living-off-the-Land attack: PowerDrop

ID: f720954f-3f64-5e5f-9497-5f0cd5e1e481

STIX ID: report--f720954f-3f64-5e5f-9497-5f0cd5e1e481

Feed Name: ThreatLocker Blog

Threat Score
78/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

Adlumin researchers uncovered ‘PowerDrop’, a living‑off‑the‑land PowerShell RAT targeting the U.S. aerospace/defense sector that uses WMI event filters for remote execution, ICMP-based heartbeat (120s interval), and single-command PowerShell launches (no persistent PS1) to stealthily map networks and exfiltrate host and network details to a C2 server; recommended mitigations include application containment, ringfencing, and Zero Trust controls to prevent PowerShell from calling out.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.