Blackpoint Cyber reported an intrusion at an industrial organization in which attackers deployed PCHunter64.exe from the unusual path C:\PerfLogs, alongside AnyDesk, FileZilla, MASSCAN, and RDP activity across seven endpoints. Investigators observed failed ADMIN$ share mount attempts by two user accounts on one machine, indicating attempted lateral movement, and Blackpoint said it isolated affected systems within minutes before issuing remediation guidance. The incident underscores continued abuse of legitimate or allowlisted Windows administration and remote-access tools in operational environments.
Sandbox analysis of PCHunter64 shows the tool can go well beyond administration, including dropping signed driver components, creating Windows service registry entries such as PCHUNTER64, loading kernel drivers, deleting SafeBoot registry keys, and exhibiting anti-debugging and anti-VM behavior. The activity aligns with MITRE ATT&CK persistence techniques including Windows Service creation or modification (T1543.003) and boot or logon autostart execution (T1547.008), while additional indicators pointed to credential-access behavior, including an artifact consistent with LSASS minidump collection. Together, the references show how a dual-use utility can be weaponized for persistence, defense evasion, and deeper compromise inside Windows environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Following escalation of the April 22, 2024 incident, Blackpoint isolated all affected endpoints within minutes, notified the partner, and provided remediation guidance.
On April 22, 2024, Blackpoint MDR detected PCHunter64.exe executing from C:\PerfLogs during an intrusion affecting an industrial organization. Investigators identified seven impacted endpoints and observed additional attacker activity involving FileZilla, MASSCAN, AnyDesk, and RDP.
A Hybrid Analysis sandbox report documented PCHunter64.exe exhibiting spyware, credential-access, persistence, defense-evasion, and network communication behaviors, including creation of Windows service registry entries and dropped driver components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
blackpointcyber.com
Open sourcehybrid-analysis.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.