PowerPool Backdoor Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, PowerPool is delivered via spam or phishing campaigns containing Symbolic Link (.slk) files. When opened, these files can be automatically loaded by Microsoft Excel to execute a PowerShell script. This script then downloads and installs PowerPool.
Once installed on a device, PowerPool initiates a first-stage module that collects system information and performs network reconnaissance. It will then download and execute a secondary backdoor module that will attempt to gain persistence. Once this is achieved the threat actors use five open-source tools (FireMaster, PowerDump, PowerSploit, SMBExec and Quarks PwDump) to traverse the network.
Remediation advice
Users are encouraged to review Microsoft Windows Privilege Escalation Vulnerability CC-2646 for guidance on the ALPC vulnerability.Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 12:52 pm