← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
“Hack-for-hire” DeathStalker Actor Uses New PowerPepper Implant
"While tracking DeathStalker’s Powersing-based activities in May 2020, we detected a previously unknown implant that leveraged DNS over HTTPS as a C2 channel, as well as parts of its delivery chain. We named this new malware “PowerPepper”. We first spotted a variant of PowerPepper in the wild in mid-July 2020, as dropped from a Word Document that had been submitted on a public multiscanner service. PowerPepper implant and associated delivery chain has been continuously developed and operated since."
Indicators of Compromise (1 / 30 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 46afa83e0b43fdb9062dd3e5fb7805997c432dd96f09ddf81f2162781daaf834 | SHA256 of 871d64d8330d956593545dfff069194e | 2020-12-03 |