logo

Malspam campaign delivering PowerDash – a tiny PowerShell backdoor

ID: 5253e0b4-b8b7-570c-921c-30ce25a21297

STIX ID: report--5253e0b4-b8b7-570c-921c-30ce25a21297

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2023-05-09

Date Updated: 2026-04-19

Author: Michał Praszmo

...
...

CERT.PL observed a malspam campaign distributing a newly identified PowerShell malware family called "PowerDash" that leverages CVE-2017-0199 in malicious Word attachments to deliver HTA-based stagers; the stagers install persistence via mshta.exe, fetch an obfuscated PowerShell payload that enumerates host details and registers with a Python/Django C2 at /dash/post_data/, and supports remote command execution. The report contains analysis of the lure, HTA/stager mechanics, deobfuscation steps, C2 internals, and a table of IoCs (IPs, URLs, and SHA256 hashes) for detection and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.