Netskope Threat Labs

Poweliks

ATP Sandbox Adv. HeuristicsAV

Poweliks is fileless malware that resides only in the Windows registry, executing through encoded JavaScript launched by the run key and never writing an executable to disk. Its design defeated file scanning entirely and inspired a wave of similar registry resident families. Researchers first observed it in 2014 campaigns that arrived through malicious documents, and its name became shorthand for fileless persistence techniques that defenders still counter today.

First seen
June 2022
Last seen
October 2026
Alert Name
Dropped:Generic.Pwshell.Poweliks.A.48C68388
Dump:Generic.Pwshell.Poweliks.A.FFFFFFFE
Exploit.Poweliks.Gen.5
Gen:Variant.Poweliks.1
Gen:Variant.Poweliks.5
Gen:Variant.Poweliks.8
Generic.Pwshell.Poweliks.A.1E7400A3
Generic.Pwshell.Poweliks.A.3AA0620B
Generic.Pwshell.Poweliks.A.3B23CE6A
Generic.Pwshell.Poweliks.A.C417466B