A new PowerShell backdoor appears to be being used by hackers from the Iranian state-run APT35 group , also known as " Charming Kitten " or " Phosphorus ", for Log4Shell attacks .
See also: Hackers infected with their own RAT malware

The payload can handle C2 communications, perform system enumeration, and ultimately receive, decrypt, and load additional modules.
Log4Shell exploits CVE-2021-44228, a critical remote code execution vulnerability in Apache Log4j, which was disclosed in December.
According to researchers at Check Point, the APT35 group was among the first to exploit the vulnerability before targets had time to apply security updates, scanning for vulnerable systems just days after its public disclosure.
Check Point, which is monitoring these efforts, attributes the exploit activity to the APT35 group, as the attacks were hastily orchestrated using previously exposed infrastructure known to be used by the group.
Analysts also identified a new PowerShell backdoor called “CharmPower.”
The CVE-2021-44228 results in the execution of a PowerShell command with a base64, ultimately retrieving the “CharmPower” module from an Amazon S3 bucket controlled by the malicious actors.
See also: PowerShell 7.2: Available and integrated into Microsoft Update
This basic unit can perform the following main functions:
Network Connection Validation – During execution, the script waits for an active internet connection, making HTTP POST requests to google.com with the parameter hi=hi.
Basic System Enumeration – The script collects the Windows operating system version, computer name, and the contents of a Ni.txt file in the $APPDATA path . The file is likely created and populated by different modules that will be retrieved from the main module.
C&C domain retrieval – The malware decodes the C&C domain retrieved from a hardcoded URL hxxps://s3[.]amazonaws[.]com/doclibrarysales/3 located in the same S3 bucket from which the backdoor was downloaded.
Download, decrypt and execute monitoring modules.

The base module continues to send HTTP POST requests to the C2 which either remain unanswered or receive a Base64 string that initiates the download of an additional PowerShell or C# module.
“CharmPower” is responsible for decrypting and loading these modules and then creating an independent communication channel with C2.
See also: Intezer: SysJoker backdoor targets Windows, Linux and macOS
The additional units sent from C2 are as follows:
Applications – Lists uninstall registry values and uses the “wmic” command to understand which applications are installed on the infected system.
Screenshots – Captures screenshots according to a specified frequency and uploads them to an FTP server using hardcoded credentials.
Process – Grabs running processes using the task list command.
System Information – Runs the “systeminfo” command to collect system information.
Command Execution – Remote command execution module that has Invoke-Expression, cmd, and PowerShell options.
Cleanup – A module for removing all traces left on the compromised system, such as registry entries and startup folders, files, and processes.
Check Point observed similarities between “CharmPower” and an Android spyware used by the APT35 group in the past, including implementing the same logging functions and using the same format and syntax.
