Malware.View on attack.mitre.org
Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret. It has appeared to be operating undetected since 2017 and was mostly observed in higher education organizations. The goal of Proxysvc is to deliver additional payloads to the target and to maintain control for the attacker. It is in the form of a DLL that can also be executed as a standalone process.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Proxysvc searches the local system and gathers data. |
| T1012 Query Registry |
Proxysvc gathers product names from the Registry key: |
| T1016 System Network Configuration Discovery |
Proxysvc collects the network adapter information and domain/username information based on current remote sessions. |
| T1041 Exfiltration Over C2 Channel |
Proxysvc performs data exfiltration over the control server channel using a custom protocol. |
| T1057 Process Discovery |
Proxysvc lists processes running on the system. |
| T1059.003 Windows Command Shell |
Proxysvc executes a binary on the system and logs the results into a temp file by using: |
| T1070.004 File Deletion |
Proxysvc can delete files indicated by the attacker and remove itself from disk using a batch file. |
| T1071.001 Web Protocols |
Proxysvc uses HTTP over SSL to communicate commands with the control server. |
| T1082 System Information Discovery |
Proxysvc collects the OS version, country name, MAC address, computer name, and physical memory statistics. |
| T1083 File and Directory Discovery |
Proxysvc lists files in directories. |
| T1119 Automated Collection |
Proxysvc automatically collects data about the victim and sends it to the control server. |
| T1124 System Time Discovery |
As part of the data reconnaissance phase, Proxysvc grabs the system time to send back to the control server. |
| T1485 Data Destruction |
Proxysvc can overwrite files indicated by the attacker before deleting them. |
| T1569.002 Service Execution |
Proxysvc registers itself as a service on the victim’s machine to run as a standalone process. |
| T1680 Local Storage Discovery |
Proxysvc collects volume information for all drives on the system. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.