ProCC

Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:13:40

Targeted industries: retail-and-hospitality

Context

ProCC is a threat actor targeting the hospitality sector with remote access Trojan malware. They use email attachments to exploit vulnerabilities like CVE-2017-0199 and deploy customized versions of RATs such as RevengeRAT, NjRAT, NanoCoreRAT, and 888 RAT. ProCC's malware is capable of collecting data from the clipboard and printer spooler, as well as capturing screenshots on infected machines.

Exploited vulnerabilities

  • CVE-2017-0199 (vulnerability)

Reports & references

  • Kaspersky — 95229 (report)

External references