Unknown threat actor targets U.S. aerospace industry with advanced PowerShell-based malware, PowerDrop

Cybersecurity researchers have discovered an unknown threat actor targeting US Aerospace companies with a new form of highly advanced cybersecurity threat – a PowerShell-based malware called PowerDrop. The actor behind this malware has been using advanced techniques such as deception, encoding, and encryption to evade initial detection and access victim networks.

Experts have analyzed the code and found that the name “PowerDrop” comes from the tool used to create the script – Windows PowerShell, and the code for padding – “Drop” (DRP). This indicates that the attackers are likely advanced and have significant knowledge of scripting and coding.

Attackers are using this malware as a post-exploitation tool to gather information from victim networks after obtaining initial access through other means. They use the network’s own defenses, such as existing access privileges, to act as a cover for their offensive actions and further improve their ability to infiltrate and compromise the target system.

To hide their activity and evade detection, PowerDrop uses advanced techniques such as employing ICMP echo request messages as beacons to initiate communication with the command-and-control (C2) server. This message is then responded to by the server with an encrypted command that is decoded and run on the compromised host. A similar ICMP ping message is used for exfiltrating the results of the instruction.

The malware also executes the PowerShell command by means of the Windows Management Instrumentation (WMI) service, indicating the adversary’s attempts to leverage living-off-the-land tactics to sidestep detection. Through this method, the attackers can execute commands with lower friction. However, it may also provide clues that enable security researchers to identify and track them.

While the core DNA of the threat is not particularly sophisticated, its ability to obfuscate suspicious activity and evade detection by endpoint defenses indicates the involvement of more sophisticated threat actors. Security experts believe that the actor behind PowerDrop may have significant resources, knowledge, and access, suggesting links to an organized cybercriminal group or even a nation-state.

The attack on the US aerospace industry comes amid increasing concerns about the vulnerability of critical infrastructure to cyberattacks. Cybercriminals and nation-states are increasing their offensive cybersecurity activities, targeting strategic industries like energy, manufacturing, healthcare, and defense. They are using advanced techniques and tactics like this latest PowerDrop malware to bypass sophisticated cyber defenses and infiltrate even the most secure systems.

Mark Sangster, Vice President of Strategy at Adlumin, commented, “The use of living-off-the-land tactics is a common approach taken by cybercriminals to fly under the radar of existing endpoint defenses. While not a sophisticated form of malware, it is still capable of executing multiple commands on a single host and compromising a network. Unfortunately, once intruders have gained access to a network, it is difficult to detect what happens next.”

The cybersecurity community continues to call for organizations to strengthen their cybersecurity posture and take proactive steps to secure their networks against increasingly advanced threats. This includes implementing multi-layered security measures and actively monitoring and testing existing defenses to identify and address vulnerabilities before they can be exploited. It is only by remaining vigilant and taking a comprehensive approach to cybersecurity that organizations can hope to keep pace with the rapidly evolving threat landscape and ensure the safety and security of their data, networks, and customers.

Explore more

How Can AI-First Models Transform Wealth Management?

The traditional cadence of wealth management, once anchored by the “once-a-quarter” portfolio review and heavy binders of historical data, has officially reached its expiration date in a world that demands instant clarity. Modern investors no longer find value in retrospective reports that explain what happened three months ago; instead, they seek a forward-looking partner capable of navigating market volatility as

Mega-Mergers and Boutique Firms Reshape Wealth Management

The traditional boundaries of the financial world are dissolving as a relentless wave of consolidation transforms once-independent institutions into sprawling, multi-trillion-dollar behemoths that dominate the global economic landscape. This movement is not merely a series of isolated business transactions but a fundamental shift in how capital is managed, protected, and grown for millions of investors across the globe. As the

How Can CRM Intelligence Redefine the Modern Guest Experience?

Traveling today often feels like navigating a digital assembly line where every interaction is perfectly timed but utterly devoid of actual warmth or personal recognition. While technology promised to bring hosts and guests closer together, it frequently serves as a barrier that reduces a human being to a single confirmation number. The hospitality industry currently grapples with a confusing paradox:

How Will Google’s New AI Lookalike Signals Impact Your Ads?

Digital marketers are currently witnessing the complete dismantling of the traditional audience silos that once provided a sense of security and predictable reach within the Google Ads ecosystem. For years, the ability to define a specific similarity percentage offered a semblance of control over who saw an advertisement and why. However, the current transition marks the definitive end of that

Equals Money Accelerates Embedded Finance via BaaS Solutions

The global financial landscape is currently undergoing a radical transformation where the traditional barriers between commerce and banking are dissolving into a single, fluid digital experience. While the prospect of a multi-billion-dollar embedded finance market is undeniably enticing, many organizations still find their ambitious roadmaps stalled by the immense complexity of the global financial grid. Integrating financial services into non-financial