PCShare is an open-source Windows remote access trojan and backdoor used by multiple Chinese threat actors for persistent remote control and cyberespionage. Its publicly available code has enabled customized deployments across distinct intrusion campaigns. Its capabilities include interactive remote desktop access, shell command execution, bidirectional file transfer, downloading and executing files, process and Windows Registry manipulation, webcam video capture, self-updating, and modification of command-and-control settings. It can query the Registry, upload files and host information to command-and-control servers, and remove its registry-based persistence mechanisms.
Observed deployments include 32-bit and 64-bit loaders, encrypted payloads and configuration, reflective loading, and injection into legitimate Windows processes. Customized versions establish persistence through COM hijacking and disguise their droppers as Windows Update components. Other deployments use DLL side-loading through legitimate NVIDIA software. Chinoxy has also been used to deploy PCShare; the initial infection vector in that government-targeting campaign was not established.
PCShare has been used by RedFoxtrot, Soft Cell, and BRONZE EDGEWOOD, and customized instances have appeared in Operation Redbonus. Documented campaigns include government-sector espionage and intrusions into telecommunications providers in Southeast Asia. PCShare is also the code base for RtlShare, a modified backdoor used by Space Pirates. Its availability and use by multiple actors mean that its presence alone does not establish threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During our investigations, we also spotted other backdoors in use, such as Whitebird, IceFog and a customized instance of PCShare.
BRONZE EDGEWOOD ... Tools ... Chinoxy, Cobalt Strike, FunnyDream, Md_client, Nishang Post Exploitation Framework, PCShare, Zuguo
In recent times, RedFoxtrot has increasingly favored the use of PCShare, PlugX, and ShadowPad, with the group’s use of IceFog, Poison Ivy, and Royal Road declining.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
the attackers were able to execute them remotely using WMI and by creating scheduled tasks remotely to run them
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
PcShare was executed via a Loader DLL (NvSmartMax.dll) and a Payload (NvSmartMax.dat) attempting to masquerade as a legitimate module by NVIDIA
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
Bisonal has deleted Registry keys to clean up its prior activity ... FIN8 has deleted Registry keys during post compromise cleanup activities ... SUNBURST ... deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
Using Recorded Future adversary infrastructure detection methods, we identified that a large proportion of the RedFoxtrot domains are linked to AXIOMATICASYMPTOTE and PlugX C2 infrastructure. Many of these were also used as C2s for different malware families, such as PCShare.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PCShare is an open-source backdoor observed on overlapping infrastructure with the Talisman PlugX campaign, helping support infrastructure clustering and attribution.
Listed as a tool used by the BRONZE EDGEWOOD threat profile.
A backdoor used to maintain foothold, with capabilities including file system control, service manipulation, file upload/download, process manipulation, registry changes, arbitrary command execution, and system reboot/shutdown. In this campaign it was side-loaded via a fake NVIDIA-themed DLL and used to launch follow-on activity including Cobalt Strike.
Malware payload observed injected into logagent.exe and rdpclip.exe.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.