PocoProxy is a previously unidentified custom command-and-control implant family documented by Sophos during Operation Crimson Palace, a Chinese state-directed cyberespionage campaign targeting a prominent Southeast Asian government organization and additional regional government and public service entities. Sophos associated PocoProxy with Cluster Charlie (STAC1305), which deployed multiple PocoProxy implants to establish persistence on compromised systems and rotate to new external C2 infrastructure. Reported capabilities include executing shell commands, injecting payloads into elevated processes, scanning processes to locate Explorer.exe, and supporting proxying/C2 communications. Sophos also reported multiple implant instances or filenames associated with PocoProxy, including 443.txt, 4413.txt, chrome.log, aaaa.txt, and a8.txt. Cluster Charlie used PocoProxy alongside scheduled tasks, WinRS, SMB shares, runas, and other access-management tradecraft, and Sophos noted that after defenders blocked PocoProxy implants in August 2023, the operators shifted C2 channels and varied deployment methods before later resuming activity via web shells. High-confidence campaign context ties PocoProxy to long-term espionage activity involving reconnaissance, credential access, lateral movement, persistence, and collection of sensitive military, political, infrastructure, and credential data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Appearing to highly prioritize access management, the actor deployed multiple implants of a previously unidentified malware, dubbed PocoProxy, to establish persistence on target systems and rotate to new external C2 infrastructure.
Appearing to highly prioritize access management, the actor deployed multiple implants of a previously unidentified malware, dubbed PocoProxy, to establish persistence on target systems and rotate to new external C2 infrastructure.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The actor created several scheduled tasks throughout the intrusion to execute the renamed mscorsvw.exe binary and sideload the malicious mscorsvc.dll (CCoreDoor) onto different machines.
dnscmd . /EnumRecords <domain> ... dsquery server ... ping sweeps of over 1800 machines.
Cluster Bravo activity was primarily focused on using valid accounts to spread laterally throughout the network... Use of renamed versions of a signed side-loadable binary (mscorsvw.exe) to obfuscate backdoor deployment and move laterally from the beachhead host to other remote servers... discovery and lateral movement efforts continued over the next several months.
the overall goal behind the campaign was to maintain access to the target network for cyberespionage... deploying various malware implants for command-and control (C2) communications... Use of multiple persistent C2 channels including Merlin Agent, PhantomNet backdoor, RUDEBIRD malware, EAGERBEE malware, and PowHeartBeat backdoor... Deployment of several samples of... PocoProxy for persistent C2 communications.
Dormant C2 communications via DNS requests and TCP network connections continued for approximately two days.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously unidentified malware family that supports shell command execution, payload injection, process scanning, and proxy/C2 operations in listen or connect modes.
A custom command-and-control implant/backdoor used by Cluster Charlie. It provided persistent access and was later replaced or supplemented by other tooling after defenders blocked it.
Previously unreported malware used to establish persistent C2 communications and support rotating external command-and-control infrastructure.
A custom C2 implant/backdoor used by Cluster Charlie for command-and-control and persistent access. It was blocked by defenders, after which the actors shifted to alternate tooling and deployment methods.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.