PcShare is a backdoor/RAT used against Windows systems. The provided content attributes it to multiple China-linked intrusion sets and clusters, including RedFoxtrot, Tropic Trooper, Soft Cell, and Space Pirates, and notes Space Pirates used a modified PcShare variant. Reported capabilities include querying/searching the Windows Registry on compromised hosts, capturing camera video, taking screenshots, uploading files and host information to command-and-control servers, and deleting its persistence mechanisms from the Registry. Observed execution and evasion behaviors include use of rundll32.exe, injection of the payload into logagent.exe and rdpclip.exe, and masquerading as wuauclt.exe to resemble the legitimate Windows Update AutoUpdate Client. A documented persistence artifact is creation of the registry key HKCU\Software\Classes\CLSID{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32. In Soft Cell activity targeting Southeast Asian telecommunications providers, PcShare was executed via a loader DLL (NvSmartMax.dll) and payload (NvSmartMax.dat) masquerading as NVIDIA components, often side-loaded by the legitimate nvSmarEx.exe and in some cases executed via rundll32.exe. The content also references a Cylance report titled "PcShare Backdoor Attacks Targeting Windows Users with FakeNarrator Malware" published on 2019-09-25.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In recent times, RedFoxtrot has increasingly favored the use of PCShare, PlugX, and ShadowPad, with the group’s use of IceFog, Poison Ivy, and Royal Road declining.
In recent times, RedFoxtrot has increasingly favored the use of PCShare, PlugX, and ShadowPad, with the group’s use of IceFog, Poison Ivy, and Royal Road declining.
In recent times, RedFoxtrot has increasingly favored the use of PCShare, PlugX, and ShadowPad, with the group’s use of IceFog, Poison Ivy, and Royal Road declining.
The report As an example, when looking at the report of attacks called “PcShare Backdoor Attacks Targeting Windows Users with FakeNarrator Malware”, published by Cylance on the 25th of September 2019...
22 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
Bisonal has deleted Registry keys to clean up its prior activity ... FIN8 has deleted Registry keys during post compromise cleanup activities ... SUNBURST ... deleted previously-created Image File Execution Options (IFEO) Debugger registry values and registry keys related to HTTP proxy to clean up traces of its activity.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
"Agent Tesla can capture screenshots of the victim’s desktop"; "AppleSeed can take screenshots on a compromised host"; "APT28 has used tools to take screenshots from victims"; "Cobalt Strike's Beacon payload is capable of capturing screenshots"; "PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals"; "Hydraq includes a component based on the code of VNC that can stream a live feed of the desktop"
Using Recorded Future adversary infrastructure detection methods, we identified that a large proportion of the RedFoxtrot domains are linked to AXIOMATICASYMPTOTE and PlugX C2 infrastructure. Many of these were also used as C2s for different malware families, such as PCShare.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware payload observed injected into logagent.exe and rdpclip.exe.
Publicly available backdoor codebase referenced as a foundation for multiple payloads in this activity. Strings/command structure in delivered payloads match open PcShare code; also serves as the base for the custom RtlShare variant with a proprietary execution chain.
Backdoor malware discussed in the context of attacks targeting Windows users and linked in the report with FakeNarrator malware.
Malware that searches registry files on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.