Description
PowGoop is a detection name for PowerShell based malware that downloads and stages additional payloads on infected systems. Scripts in this class fetch encoded content, often disguised as images, decode it, and execute it entirely in memory to avoid disk based detection. Researchers have tied Powgoop chains to Iranian state sponsored actors, and detections indicate an active staged intrusion rather than an isolated file infection.
Stats
- First seen
- April 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
8 techniques across 3 tactics.
TA0005 Stealth
Associated groups
Alert name variants
| Alert Name |
|---|
| Win32.Trojan.Powgoop |