Description
PowerCat is a PowerShell networking tool in the style of netcat that gives operators TCP/IP communication channels on compromised systems. The HAFNIUM threat group used it alongside Cobalt Strike and other tooling in its campaigns against Microsoft Exchange servers. Because legitimate security testing also uses such tools, defenders should triage its detections against authorized activity.
Stats
- First seen
- April 2022
- Last seen
- October 2026
Also known as
Powercat
Alert name variants
| Alert Name |
|---|
| Application.Tool.PowerCat.A |
| Generic.Trojan.HackTool.PowerCat.A.18E7EF84 |
| Generic.Trojan.HackTool.PowerCat.A.1EC2FA71 |
| Generic.Trojan.HackTool.PowerCat.A.3452DD20 |
| Generic.Trojan.HackTool.PowerCat.A.5B10B295 |
| Generic.Trojan.HackTool.PowerCat.A.7AF2F8D9 |
| Generic.Trojan.HackTool.PowerCat.A.858B4A48 |
| Generic.Trojan.HackTool.PowerCat.A.8D85D5A5 |
| Generic.Trojan.HackTool.PowerCat.A.C00094AD |
| Generic.Trojan.HackTool.PowerCat.A.F2F54827 |