Pcexter

S1102

Malware.View on attack.mitre.org

About this malware

Pcexter is an uploader that has been used by ToddyCat since at least 2023 to exfiltrate stolen files.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1005
Data from Local System

Pcexter can upload files from targeted systems.

T1083
File and Directory Discovery

Pcexter has the ability to search for files in specified directories.

T1567.002
Exfiltration to Cloud Storage

Pcexter can upload stolen files to OneDrive storage accounts via HTTP `POST`.

T1574.001
DLL

Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Kaspersky ToddyCat Check Logs October 2023 Open source
    Dedola, G. et al. (2023, October 12). ToddyCat: Keep calm and check logs. Retrieved January 3, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.