An Iranian state-backed hacking group is now deploying a new backdoor called PowerLess. The group also used the previously unknown malware to deploy additional modules, including info stealers and keyloggers. The PowerLess backdoor features encrypted command-and-control communication channels, and it allows executing commands and killing running processes on compromised systems. In November, the Microsoft Threat Intelligence Center said it has been tracking six different Iranian threat groups who have been deploying ransomware and exfiltrating data in attacks as far back as September 2020.”]

