PcShare is an open-source Windows backdoor widely observed in Chinese espionage operations. It has been used by multiple China-aligned intrusion sets, including activity attributed to RedFoxtrot and Soft Cell, and has also appeared in reporting tied to Tropic Trooper and other campaigns targeting telecommunications, government, defense, and organizations in Southeast Asia and South Asia. Operators have commonly deployed it alongside other post-compromise tooling such as China Chopper, Cobalt Strike, PlugX, and ShadowPad.
PcShare functions as a remote access backdoor for post-exploitation control of compromised hosts. Documented capabilities include uploading files and host information to command-and-control infrastructure, taking screenshots, capturing camera video, querying and searching the Windows Registry, and removing its own persistence-related registry artifacts. It has also been observed injected into legitimate Windows processes as a defense-evasion measure.
In intrusions against telecom providers, PcShare was used for persistence and remote control after exploitation of Microsoft Exchange vulnerabilities and deployment of web shells. Delivery has been observed through DLL sideloading using legitimate executables and malicious loader components masquerading as benign software. Persistence has been established through scheduled tasks and registry-based mechanisms, including COM hijacking-style registry entries. Samples have also been disguised with names resembling legitimate Windows components to reduce suspicion.
PcShare is best characterized as a publicly available backdoor that remains operationally relevant because threat actors adapt and repackage it for long-term espionage access on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BRONZE EDGEWOOD ... Tools ... Chinoxy, Cobalt Strike, FunnyDream, Md_client, Nishang Post Exploitation Framework, PCShare, Zuguo
In recent times, RedFoxtrot has increasingly favored the use of PCShare, PlugX, and ShadowPad, with the group’s use of IceFog, Poison Ivy, and Royal Road declining.
In recent times, RedFoxtrot has increasingly favored the use of PCShare, PlugX, and ShadowPad, with the group’s use of IceFog, Poison Ivy, and Royal Road declining.
The report As an example, when looking at the report of attacks called “PcShare Backdoor Attacks Targeting Windows Users with FakeNarrator Malware”, published by Cylance on the 25th of September 2019...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
the attackers were able to execute them remotely using WMI and by creating scheduled tasks remotely to run them
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
PcShare was executed via a Loader DLL (NvSmartMax.dll) and a Payload (NvSmartMax.dat) attempting to masquerade as a legitimate module by NVIDIA
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
Bisonal has deleted Registry keys to clean up its prior activity ... FIN8 has deleted Registry keys during post compromise cleanup activities ... SUNBURST ... deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
Using Recorded Future adversary infrastructure detection methods, we identified that a large proportion of the RedFoxtrot domains are linked to AXIOMATICASYMPTOTE and PlugX C2 infrastructure. Many of these were also used as C2s for different malware families, such as PCShare.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PCShare is an open-source backdoor observed on overlapping infrastructure with the Talisman PlugX campaign, helping support infrastructure clustering and attribution.
Listed as a tool used by the BRONZE EDGEWOOD threat profile.
A backdoor used to maintain foothold, with capabilities including file system control, service manipulation, file upload/download, process manipulation, registry changes, arbitrary command execution, and system reboot/shutdown. In this campaign it was side-loaded via a fake NVIDIA-themed DLL and used to launch follow-on activity including Cobalt Strike.
Malware payload observed injected into logagent.exe and rdpclip.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.