Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 03:22:22 UTC Home > List all groups > List all tools > List all groups using tool POWERSTAR Tool: POWERSTAR Names POWERSTAR CharmPower GorjolEcho Category Malware Type Backdoor Description (Volexity) Volexity found the latest POWERSTAR variant to be more complex and assesses that it is likely supported by a custom server-side component, which automates simple actions for the malware operator. It is also notable that this latest version of the malware has a variety of interesting features, including the use of the InterPlanetary File System (IPFS), as well as remotely hosting its decryption function and configuration details on publicly accessible cloud hosting. Information Malpedia Last change to this tool card: 27 December 2024 Download this tool card in JSON format All groups using tool POWERSTAR Changed Name Country Observed APT groups GreenCharlie 2020 Magic Hound, APT 35, Cobalt Illusion, Charming Kitten 2012-Jun 2025 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=34ed82b9-8973-4d20-81a9-5f116c1e21a4 Page 1 of 2 2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=34ed82b9-8973-4d20-81a9-5f116c1e21a4 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=34ed82b9-8973-4d20-81a9-5f116c1e21a4 Page 2 of 2