Threat actors took aim at users visiting forums with discussions on state-subsidized housing that Russian military personnel and their families are entitled to. Threat actors use PowerSploit, a modified set of PowerShell scripts, and various utilities to steal files and passwords found on the victim computer. The attack unfolds in several stages, as described below. The main module of the malicious program receives an instruction to download and launch add-on modules, which opens new capabilities for the threat actors. The malicious program is a platform used to deploy extra (add-on) malicious modules, store them stealthily and thus add new capabilities.”]
Source: https://securelist.com/a-simple-example-of-a-complex-cyberattack/82636/