Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 20:01:53 UTC Home > List all groups > List all tools > List all groups using tool POWERPLANT Tool: POWERPLANT Names POWERPLANT KillACK Category Malware Type Backdoor Description (Mandiant) POWERPLANT, also referred to as “KillACK”, is a PowerShell-based backdoor with a breadth of capabilities, initially delivered following a successful Griffon infection in August 2020. Merges involving the usage of POWERPLANT into 2021 led us to assess that FIN7 is likely the only operator using POWERPLANT. Information Malpedia Last change to this tool card: 27 December 2022 Download this tool card in JSON format All groups using tool POWERPLANT Changed Name Country Observed APT groups   FIN7 2013-Jul 2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=48ba4c0b-eea7-4d1d-adbf-537c318bf1ea https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=48ba4c0b-eea7-4d1d-adbf-537c318bf1ea Page 1 of 1