Pcexter is a Windows data-exfiltration tool used to upload stolen archive files to Microsoft OneDrive. It has been documented in ToddyCat intrusion activity as part of a broader collection-and-exfiltration workflow in which harvested files are first packaged into archives and then transferred to attacker-controlled cloud storage. Pcexter communicates with OneDrive over HTTP POST and has been associated with OAuth-based access to Microsoft cloud services for file upload operations.
Operationally, Pcexter has been executed as a malicious DLL through DLL side-loading, including deployment alongside a legitimate executable to trigger loading of the payload. In observed use, it functioned as a dedicated uploader rather than a general-purpose backdoor or loader, receiving prepared archives from companion collection tooling and sending them to cloud storage to blend exfiltration traffic with legitimate enterprise service usage.
Pcexter is best characterized as a specialized exfiltration utility within an espionage toolchain. Its known behavior supports theft of collected files from compromised Windows environments, particularly where operators seek to abuse trusted cloud platforms for stealthier data removal.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Pcexter: This is another uploader used to exfiltrate archive files to Microsoft OneDrive.”
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Many entries state malware or actors can upload, transfer, send, or exfiltrate files from compromised hosts to command-and-control servers or attacker infrastructure.
Akira will exfiltrate victim data using applications such as Rclone. APT41 DUST exfiltrated collected information to OneDrive. BoomBox can upload data to dedicated per-victim folders in Dropbox. During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
OneDrive exfiltration utility (DLL side-loaded as Vspmsg.dll using a legitimate Visual Studio binary) that waits on event Global\SystemLocalPcexter, searches for files by mask in a specified directory, obtains OAuth2 tokens from login.microsoftonline.com, and uploads via HTTP POST; supports proxy and proxy credentials.
Exfiltration tool used to upload collected archives to OneDrive.
Malware that uploads stolen files to OneDrive via HTTP POST.
Malware distributed and executed as Vspmsg.dll via DLL side-loading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.