PcShare

MITRE ATT&CK: S1050 View on attack.mitre.org

Aliases: PcShare

First seen
2018-11-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
3 (1 malicious)
Last IoC activity
2026-08-25 05:23:04
Profile updated
2026-07-07 12:39:54

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn

Context

PcShare is an open source remote access tool that has been modified and used by Chinese threat actors, most notably during the FunnyDream campaign since late 2018.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to PcShare (S1050). The 1 most recently updated:

TypeIndicatorUpdatedSources
IP address 193.239.166.54 2026-09-02 1

Detection coverage

  • 1 YARA rules
  • 299 Sigma rules

Malware & tools used

  • Match Legitimate Resource Name or Location (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Discovery (attack-pattern)
  • Screen Capture (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Compression (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Component Object Model Hijacking (attack-pattern)
  • Keylogging (attack-pattern)
  • Data from Local System (attack-pattern)
  • Rundll32 (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Query Registry (attack-pattern)
  • File Deletion (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Invalid Code Signature (attack-pattern)
  • Modify Registry (attack-pattern)
  • Native API (attack-pattern)
  • Process Injection (attack-pattern)
  • Video Capture (attack-pattern)

Used by threat actors

  • FunnyDream (campaign)
  • APT5 (threat-actor)

Detection rules

  • MALPEDIA_Win_Pcshare_Auto (yara-rule)

Reports & references

  • go.recordedfuture.com — Cta 2021 0616 (report)
  • bitdefender.com — Bitdefender Whitepaper Chinese Apt (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pcshare (report)
  • web.archive.org — Pcshare Backdoor Attacks Targeting Windows Users With Fakenarrator Malware (report)
  • MITRE ATT&CK — S1050 (report)
  • github.com — Pcshare (report)

External references