Netskope Threat Labs

PowGoop

ATP Sandbox Adv. Heuristics

PowGoop is a detection name for PowerShell based malware that downloads and stages additional payloads on infected systems. Scripts in this class fetch encoded content, often disguised as images, decode it, and execute it entirely in memory to avoid disk based detection. Researchers have tied Powgoop chains to Iranian state sponsored actors, and detections indicate an active staged intrusion rather than an isolated file infection.

First seen
April 2022
Last seen
October 2026

8 techniques across 3 tactics.

TA0002 Execution

TA0005 Stealth

TA0011 Command and Control

Alert Name
Win32.Trojan.Powgoop