Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 23:22:25 UTC Home > List all groups > List all tools > List all groups using tool PowerMagic Tool: PowerMagic Names PowerMagic Category Malware Type Backdoor Description (Kaspersky) The script manutil.vbs, which is dropped by the initial package, is a loader for a previously unknown backdoor written in PowerShell that we named PowerMagic. Information Malpedia Last change to this tool card: 22 June 2023 Download this tool card in JSON format All groups using tool PowerMagic Changed Name Country Observed APT groups Bad Magic, RedStinger [Unknown] 2020-May 2023 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=87516d91-5f8e-4571-a1df-4086e1a30e04 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=87516d91-5f8e-4571-a1df-4086e1a30e04 Page 1 of 1