Proxysvc
MITRE ATT&CK: S0238 View on attack.mitre.org
Aliases: Proxysvc
- First seen
- 2017-01-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:30:47
Targeted industries: education-and-nonprofits
Context
Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret. It has appeared to be operating undetected since 2017 and was mostly observed in higher education organizations. The goal of Proxysvc is to deliver additional payloads to the target and to maintain control for the attacker. It is in the form of a DLL that can also be executed as a standalone process.
Detection coverage
- 227 Sigma rules
Malware & tools used
- Data from Local System (attack-pattern)
- Web Protocols (attack-pattern)
- File Deletion (attack-pattern)
- Automated Collection (attack-pattern)
- Service Execution (attack-pattern)
- Local Storage Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Query Registry (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- System Time Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Data Destruction (attack-pattern)
Used by threat actors
- Lazarus Group (threat-actor)
Reports & references
- MITRE ATT&CK — S0238 (report)
- McAfee — Analyzing Operation Ghostsecret Attack Seeks To Steal Data Worldwide (report)