PcShare
MITRE ATT&CK: S1050 View on attack.mitre.org
Aliases: PcShare
- First seen
- 2018-11-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 3 (1 malicious)
- Last IoC activity
- 2026-08-25 05:23:04
- Profile updated
- 2026-07-07 12:39:54
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn
Context
PcShare is an open source remote access tool that has been modified and used by Chinese threat actors, most notably during the FunnyDream campaign since late 2018.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to PcShare (S1050). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 193.239.166.54 | 2026-09-02 | 1 |
Detection coverage
- 1 YARA rules
- 299 Sigma rules
Malware & tools used
- Match Legitimate Resource Name or Location (attack-pattern)
- Web Protocols (attack-pattern)
- Process Discovery (attack-pattern)
- Screen Capture (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Compression (attack-pattern)
- Windows Command Shell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Component Object Model Hijacking (attack-pattern)
- Keylogging (attack-pattern)
- Data from Local System (attack-pattern)
- Rundll32 (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Query Registry (attack-pattern)
- File Deletion (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Invalid Code Signature (attack-pattern)
- Modify Registry (attack-pattern)
- Native API (attack-pattern)
- Process Injection (attack-pattern)
- Video Capture (attack-pattern)
Used by threat actors
- FunnyDream (campaign)
- APT5 (threat-actor)
Detection rules
- MALPEDIA_Win_Pcshare_Auto (yara-rule)
Reports & references
- go.recordedfuture.com — Cta 2021 0616 (report)
- bitdefender.com — Bitdefender Whitepaper Chinese Apt (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pcshare (report)
- web.archive.org — Pcshare Backdoor Attacks Targeting Windows Users With Fakenarrator Malware (report)
- MITRE ATT&CK — S1050 (report)
- github.com — Pcshare (report)