Skip to main content
QUIETLYTIC
Malware

Empire

Open-source, cross-platform post-exploitation framework, per MITRE ATT&CK, written in Python with PowerShell-based Windows agents, singled out in a joint government report on widely abused public hacking tools.

Threat Level
HIGH
Family
Empire
Type
OTHER
Also Known As
EmPyre, PowerShell Empire

Overview

Empire (MITRE ATT&CK ID S0363) is an open-source, cross-platform remote administration and post-exploitation framework publicly available on GitHub, per MITRE’s software profile. MITRE documents the tool as primarily written in Python, with post-exploitation agents written in pure PowerShell for Windows and Python for Linux/macOS. MITRE’s citations note Empire was one of five tools singled out by a joint government report on public hacking tools being widely used by adversaries — placing it in the same “dual-use, widely abused” category as Cobalt Strike and Mimikatz.

Actors documented using this tool (per MITRE ATT&CK relationship data)

Our ingested data links Empire to at least 14 distinct MITRE ATT&CK groups, including Indrik Spider, APT41, MuddyWater, Sandworm Team, Leviathan, Turla, and Wizard Spider.

Notable techniques (per MITRE ATT&CK relationship data)

Techniques MITRE links to Empire in our data include Access Token Manipulation (T1134), Accessibility Features (T1546.008), Archive Collected Data (T1560), Asymmetric Cryptography (T1573.002), Automated Collection (T1119), and Bidirectional Communication (T1102.002).

What we don’t have

MITRE’s ingested data doesn’t include a discovery/first-observed date for software entries. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no data on how much of Empire’s documented usage is from the original open-source project versus forked/modified variants.

Frequently Asked Questions

What is Empire? An open-source, cross-platform post-exploitation framework, per MITRE ATT&CK, with PowerShell-based Windows agents — one of five tools a joint government report specifically flagged as widely abused public hacking tools.

Is Empire the same as PowerShell Empire? Yes — MITRE ATT&CK tracks “PowerShell Empire” and “EmPyre” as aliases of the same tool.

Which threat groups use Empire? Per MITRE ATT&CK’s relationship data, at least 14 tracked groups, including APT41, Sandworm Team, Turla, and MuddyWater.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), software ID S0363, aggregated August 26, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more malware profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools