Proxysvc

S0238

Malware.View on attack.mitre.org

About this malware

Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret. It has appeared to be operating undetected since 2017 and was mostly observed in higher education organizations. The goal of Proxysvc is to deliver additional payloads to the target and to maintain control for the attacker. It is in the form of a DLL that can also be executed as a standalone process.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1005
Data from Local System

Proxysvc searches the local system and gathers data.

T1012
Query Registry

Proxysvc gathers product names from the Registry key: HKLM\Software\Microsoft\Windows NT\CurrentVersion ProductName and the processor description from the Registry key HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 ProcessorNameString.

T1016
System Network Configuration Discovery

Proxysvc collects the network adapter information and domain/username information based on current remote sessions.

T1041
Exfiltration Over C2 Channel

Proxysvc performs data exfiltration over the control server channel using a custom protocol.

T1057
Process Discovery

Proxysvc lists processes running on the system.

T1059.003
Windows Command Shell

Proxysvc executes a binary on the system and logs the results into a temp file by using: cmd.exe /c "<file_path> > %temp%\PM* .tmp 2>&1".

T1070.004
File Deletion

Proxysvc can delete files indicated by the attacker and remove itself from disk using a batch file.

T1071.001
Web Protocols

Proxysvc uses HTTP over SSL to communicate commands with the control server.

T1082
System Information Discovery

Proxysvc collects the OS version, country name, MAC address, computer name, and physical memory statistics.

T1083
File and Directory Discovery

Proxysvc lists files in directories.

T1119
Automated Collection

Proxysvc automatically collects data about the victim and sends it to the control server.

T1124
System Time Discovery

As part of the data reconnaissance phase, Proxysvc grabs the system time to send back to the control server.

T1485
Data Destruction

Proxysvc can overwrite files indicated by the attacker before deleting them.

T1569.002
Service Execution

Proxysvc registers itself as a service on the victim’s machine to run as a standalone process.

T1680
Local Storage Discovery

Proxysvc collects volume information for all drives on the system.

Groups that use it1

Campaigns0

None recorded.

References1

  1. McAfee GhostSecret Open source
    Sherstobitoff, R., Malhotra, A. (2018, April 24). Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide. Retrieved May 16, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.