Unknown threat actor targets U.S. aerospace industry with advanced PowerShell-based malware, PowerDrop

Cybersecurity researchers have discovered an unknown threat actor targeting US Aerospace companies with a new form of highly advanced cybersecurity threat – a PowerShell-based malware called PowerDrop. The actor behind this malware has been using advanced techniques such as deception, encoding, and encryption to evade initial detection and access victim networks.

Experts have analyzed the code and found that the name “PowerDrop” comes from the tool used to create the script – Windows PowerShell, and the code for padding – “Drop” (DRP). This indicates that the attackers are likely advanced and have significant knowledge of scripting and coding.

Attackers are using this malware as a post-exploitation tool to gather information from victim networks after obtaining initial access through other means. They use the network’s own defenses, such as existing access privileges, to act as a cover for their offensive actions and further improve their ability to infiltrate and compromise the target system.

To hide their activity and evade detection, PowerDrop uses advanced techniques such as employing ICMP echo request messages as beacons to initiate communication with the command-and-control (C2) server. This message is then responded to by the server with an encrypted command that is decoded and run on the compromised host. A similar ICMP ping message is used for exfiltrating the results of the instruction.

The malware also executes the PowerShell command by means of the Windows Management Instrumentation (WMI) service, indicating the adversary’s attempts to leverage living-off-the-land tactics to sidestep detection. Through this method, the attackers can execute commands with lower friction. However, it may also provide clues that enable security researchers to identify and track them.

While the core DNA of the threat is not particularly sophisticated, its ability to obfuscate suspicious activity and evade detection by endpoint defenses indicates the involvement of more sophisticated threat actors. Security experts believe that the actor behind PowerDrop may have significant resources, knowledge, and access, suggesting links to an organized cybercriminal group or even a nation-state.

The attack on the US aerospace industry comes amid increasing concerns about the vulnerability of critical infrastructure to cyberattacks. Cybercriminals and nation-states are increasing their offensive cybersecurity activities, targeting strategic industries like energy, manufacturing, healthcare, and defense. They are using advanced techniques and tactics like this latest PowerDrop malware to bypass sophisticated cyber defenses and infiltrate even the most secure systems.

Mark Sangster, Vice President of Strategy at Adlumin, commented, “The use of living-off-the-land tactics is a common approach taken by cybercriminals to fly under the radar of existing endpoint defenses. While not a sophisticated form of malware, it is still capable of executing multiple commands on a single host and compromising a network. Unfortunately, once intruders have gained access to a network, it is difficult to detect what happens next.”

The cybersecurity community continues to call for organizations to strengthen their cybersecurity posture and take proactive steps to secure their networks against increasingly advanced threats. This includes implementing multi-layered security measures and actively monitoring and testing existing defenses to identify and address vulnerabilities before they can be exploited. It is only by remaining vigilant and taking a comprehensive approach to cybersecurity that organizations can hope to keep pace with the rapidly evolving threat landscape and ensure the safety and security of their data, networks, and customers.

Explore more

AI and Generative AI Transform Global Corporate Banking

The high-stakes world of global corporate finance has finally severed its ties to the sluggish, paper-heavy traditions of the past, replacing the clatter of manual data entry with the silent, lightning-fast processing of neural networks. While the industry once viewed artificial intelligence as a speculative luxury confined to the periphery of experimental “innovation labs,” it has now matured into the

Is Auditability the New Standard for Agentic AI in Finance?

The days when a financial analyst could be mesmerized by a chatbot simply generating a coherent market summary have vanished, replaced by a rigorous demand for structural transparency. As financial institutions pivot from experimental generative models to autonomous agents capable of managing liquidity and executing trades, the “wow factor” has been eclipsed by the cold reality of production-grade requirements. In

How to Bridge the Execution Gap in Customer Experience

The modern enterprise often functions like a sophisticated supercomputer that possesses every piece of relevant information about a customer yet remains fundamentally incapable of addressing a simple inquiry without requiring the individual to repeat their identity multiple times across different departments. This jarring reality highlights a systemic failure known as the execution gap—a void where multi-million dollar investments in marketing

Trend Analysis: AI Driven DevSecOps Orchestration

The velocity of software production has reached a point where human intervention is no longer the primary driver of development, but rather the most significant bottleneck in the security lifecycle. As generative tools produce massive volumes of functional code in seconds, the traditional manual review process has effectively crumbled under the weight of machine-generated output. This shift has created a

Navigating Kubernetes Complexity With FinOps and DevOps Culture

The rapid transition from static virtual machine environments to the fluid, containerized architecture of Kubernetes has effectively rewritten the rules of modern infrastructure management. While this shift has empowered engineering teams to deploy at an unprecedented velocity, it has simultaneously introduced a layer of financial complexity that traditional billing models are ill-equipped to handle. As organizations navigate the current landscape,