Living-off-the-Land attack: PowerDrop
ID: f720954f-3f64-5e5f-9497-5f0cd5e1e481
STIX ID: report--f720954f-3f64-5e5f-9497-5f0cd5e1e481
Feed Name: ThreatLocker Blog
Adlumin researchers uncovered ‘PowerDrop’, a living‑off‑the‑land PowerShell RAT targeting the U.S. aerospace/defense sector that uses WMI event filters for remote execution, ICMP-based heartbeat (120s interval), and single-command PowerShell launches (no persistent PS1) to stealthily map networks and exfiltrate host and network details to a C2 server; recommended mitigations include application containment, ringfencing, and Zero Trust controls to prevent PowerShell from calling out.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
