POSHSPY - S0150 (5e595477-2e78-4ce7-ae42-e0b059b17808)
POSHSPY is a backdoor that has been used by APT29 since at least 2015. It appears to be used as a secondary backdoor used if the actors lost access to their primary backdoors. (Citation: FireEye POSHSPY April 2017)