Netskope Threat Labs

PowerCat

ATP Sandbox Adv. HeuristicsAVNetskope IPS

PowerCat is a PowerShell networking tool in the style of netcat that gives operators TCP/IP communication channels on compromised systems. The HAFNIUM threat group used it alongside Cobalt Strike and other tooling in its campaigns against Microsoft Exchange servers. Because legitimate security testing also uses such tools, defenders should triage its detections against authorized activity.

First seen
April 2022
Last seen
October 2026
Powercat
Alert Name
Application.Tool.PowerCat.A
Generic.Trojan.HackTool.PowerCat.A.18E7EF84
Generic.Trojan.HackTool.PowerCat.A.1EC2FA71
Generic.Trojan.HackTool.PowerCat.A.3452DD20
Generic.Trojan.HackTool.PowerCat.A.5B10B295
Generic.Trojan.HackTool.PowerCat.A.7AF2F8D9
Generic.Trojan.HackTool.PowerCat.A.858B4A48
Generic.Trojan.HackTool.PowerCat.A.8D85D5A5
Generic.Trojan.HackTool.PowerCat.A.C00094AD
Generic.Trojan.HackTool.PowerCat.A.F2F54827