ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Poweliks – Malware that drops no files

Paul by Paul
August 12, 2014
in Malware, Public
Reading Time: 4 mins read
Poweliks malware
Share on FacebookShare on Twitter

A new piece of malware referred to as Poweliks tries to evade detection and analysis by operating completely from your system registry without having files on the disk, security researchers alert.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

The technique of “fileless” malware that only is present in the system’s memory isn’t new, but such threats are rare simply because they don’t live through system reboots, in the event the memory is cleared. That’s not the case for Poweliks, that takes a fairly new strategy to accomplish persistence while staying fileless, as outlined by malware researchers from G Data Software.

The Poweliks malware spreads via emails which includes a malicious Microsoft Word document. The document holds all the code required for the attack, encrypted and hidden, once executed the malicious code generates an encoded autostart registry key and to fly under the radar it keeps the registry key hidden.

Poweliks creates a registry entry that executes the legitimate rundll32.exe Windows file followed by some encoded JavaScript code. This triggers a process similar in concept to a Matryoshka Russian nesting doll, said Paul Rascagnères, senior threat researcher at G Data, in a blog post.

The JavaScript code checks whether or not Windows PowerShell, a command-line shell and scripting environment, exists on the system. When it isn’t, it downloads and installs it after which it decodes even more code that is really a PowerShell script.

After it’s successfully installed, Poweliks attempts to contact hardcoded IP addresses to receive further commands from the attacker.

Following these steps explained by Paul Rascagneres, Senior Threat Specialist at GData:
  • As the entry point, they exploit a vulnerability in Microsoft Word with the help of a crafted Word document they spread via email. The same approach would work with any other exploit.
  • After that, they make sure that the malicious activities survive system re-boot by creating an encoded autostart registry key. To remain undetected, this key is disguised/hidden.
  • Decoding this key shows two new aspects: Code which makes sure the affected system has Microsoft PowerShell installed and additional code.
  • The additional code is a Base64-encoded PowerShell script, which calls and executes the shellcode (assembly).
  • As a final step, this shellcode executes a Windows binary, the payload. In the case analyzed, the binary tried to connect to hard coded IP addresses to receive further commands, but the attackers could have triggered any other action at this point.
  • All activities are stored in the registry. No file is ever created.

In addition, the actual startup registry key made by Poweliks is a non-ASCII character. This is a trick that stops regedit, the Registry editortool, and perhaps other programs from presenting the rogue start-up entry, rendering it hard for both users and malware experts to physically see the infection.

You can read Symantec’s write up of the malware, here.

Tags: malwarePowelikstrojan
Previous Post

Chicago Yacht club breached

Next Post

Researchers uncover cryptocurrency hack causing $83,000 in damages

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.