Powerun
Overview
Executive Summary
Powerun (often detected as HackTool.Powerun, Riskware.PowerShell, or Trojan.Powerun) is not a standalone malware family, but rather a detection signature for malicious wrappers or execution utilities designed to covertly run PowerShell scripts. Threat actors use Powerun utilities to bypass local execution policies, obfuscate their malicious PowerShell payloads, and execute fileless attacks that evade traditional antivirus scanning.Technical Architecture and Exploitation
PowerShell is a highly powerful, legitimate administrative framework built into Windows. Because it is a trusted tool, attackers heavily favor it for "Living off the Land" (LotL) attacks. The "Powerun" classification typically applies to utilities that facilitate this abuse:- Execution Policy Bypass: By default, Windows restricts the execution of unsigned PowerShell scripts. Powerun tools often execute PowerShell using the `-ExecutionPolicy Bypass` flag or instantiate the PowerShell runspace directly within a custom C# or C++ executable to completely ignore local Group Policy restrictions.
- Obfuscation and Fileless Execution: Powerun wrappers frequently decode heavily obfuscated (Base64) PowerShell scripts and execute them directly in memory (`-EncodedCommand`). This means the actual malicious payload never touches the hard drive, rendering static disk scanning ineffective.
- AMSI Evasion: Advanced Powerun utilities attempt to patch or disable the Anti-Malware Scan Interface (AMSI) in memory before executing the PowerShell script, blinding the EDR solution to the script's contents.
Threat Impact
A Powerun detection is a critical indicator of compromise. It signifies that an attacker is actively attempting to execute arbitrary code on the system utilizing trusted system binaries. The payloads executed via Powerun are frequently Cobalt Strike beacons, Empire agents, or ransomware stagers.Defense and Resilience Strategies
- Constrained Language Mode (CLM): The most effective defense against malicious PowerShell usage is enforcing Constrained Language Mode via Windows Defender Application Control (WDAC). CLM severely restricts the APIs and COM objects that PowerShell can access, neutralizing most offensive scripts.
- Script Block Logging: Enable PowerShell Script Block Logging (Event ID 4104). This forces the OS to log the *de-obfuscated* content of the script as it executes, providing invaluable telemetry for incident responders.
- Behavioral Monitoring: Monitor EDR telemetry for suspicious parent-child process relationships, such as Word (`winword.exe`) or Excel (`excel.exe`) unexpectedly spawning `powershell.exe` with encoded command-line arguments.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1059.001 T1222.001 T1562.001
Tactical Mitigations
Based on the techniques used by this family, consider the following defensive strategies:
- T1059.001: Restrict execution of PowerShell. Enforce PowerShell Constrained Language Mode and Script Block Logging.
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_POWERUN {
meta:
description = "Detects Powerun (ransomware)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "powerun" ascii wide nocase
$s2 = "hacktool.powerun" ascii wide nocase
$s3 = "riskware.powershellrunner" ascii wide nocase
$s4 = "trojan.powerun" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Powerun Activity
id: 6406d0fa3280297c398aaae5ec205d3a
status: experimental
description: Detects generic indicators of the powerun malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*powerun*"
- "*hacktool.powerun*"
- "*riskware.powershellrunner*"
- "*trojan.powerun*"
condition: selection
level: mediumReferences & External Analysis
- Search "powerun" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Powerun Ransomware from Windows?
Manual removal of Powerun is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Powerun a virus or a Ransomware?
Powerun is classified as a Ransomware. Unlike traditional viruses that infect files, modern malware like Powerun typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Powerun infection?
Symptoms of Powerun can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: ransomware)
Explore other malware families in the same category:
Protect Your Network Against Ransomwares
Want to prevent Powerun and similar threats from compromising your organization? Read our comprehensive defensive guide: Ransomware Protection Guide.
Machine-readable
Get this profile as JSON: https://jordan123234-malware-families-explorer.static.hf.space/api/powerun.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.