Proxysvc

MITRE ATT&CK: S0238 View on attack.mitre.org

Aliases: Proxysvc

First seen
2017-01-01 00:00:00
Malware type
downloader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:30:47

Targeted industries: education-and-nonprofits

Context

Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret. It has appeared to be operating undetected since 2017 and was mostly observed in higher education organizations. The goal of Proxysvc is to deliver additional payloads to the target and to maintain control for the attacker. It is in the form of a DLL that can also be executed as a standalone process.

Detection coverage

  • 227 Sigma rules

Malware & tools used

  • Data from Local System (attack-pattern)
  • Web Protocols (attack-pattern)
  • File Deletion (attack-pattern)
  • Automated Collection (attack-pattern)
  • Service Execution (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Query Registry (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Data Destruction (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0238 (report)
  • McAfee — Analyzing Operation Ghostsecret Attack Seeks To Steal Data Worldwide (report)

External references