An Iranian-backed hacking group referred to as APT35 (also known as Phosphorus or Charming Kitten) is now developing a new backdoor called PowerLess.

See also: Apple and Tesla supplier hit by ransomware
The group also used an unknown malware to develop additional functional modules, including info stealers and keyloggers, according to a report published today by the Cybereason Nocturnus Team.
The PowerLess backdoor features encrypted command and control communication channels and allows for the execution of commands and the elimination of processes running on compromised systems.
It also evades detection by running within the context of a .NET application, which allows it to hide from security solutions by not launching a new PowerShell instance.
See also: QNAP NAS: Forced firmware update for DeadBolt ransomware
In January, APT35 operators deployed another previously undocumented PowerShell backdoor called CharmPower in attacks leveraging Log4Shell exploits
Connection with Memento ransomware
While examining attacks where the PowerLess backdoor was used, researchers also found possible connections to the Memento ransomware.
This ransomware has been active since April 2021, and is deployed in attacks against VMware vCenter servers using exploits designed to abuse a critical pre-auth remote code execution flaw that was patched in February 2021.

Sophos has seen Memento operators switch from encryption systems with a Python-based ransomware strain to moving files to password-protected WinRAR archives due to the ransomware protection active on compromised devices.
The links include common TTP patterns, automatically generated strings, and a domain (google.onedriver-srv[.]ml).
See also: LockBit ransomware: Linux version targets VMware ESXi servers
This domain is linked to an IP address mentioned in a joint advisory issued by US and UK cybersecurity agencies in November regarding Iranian hacking groups targeting Microsoft Exchange and Fortinet servers.
Information source: bleepingcomputer.com
