Executive Summary
Proxysvc is a Lazarus-derived DLL used stealthily since 2017 to deliver additional payloads into higher‑education systems. It functions both as an injected component and a standalone process, facilitating covert command-and-control channels. Its dual functionality allows attackers to maintain persistence while bypassing many conventional defense mechanisms, posing a serious risk to academic institutions.
Enhanced Description
Proxysvc is a clandestine Windows DLL that was employed by the North Korean Lazarus Group during its Operation GhostSecret campaign. First identified in 2017 targeting mainly higher‑education institutions, the module masquerades as legitimate software while functioning as both a loader and stand‑alone application. In DLL mode it is designed to be injected into trusted processes, allowing it to evade initial security scans by blending in with normal system activity. Once resident, Proxysvc acts primarily as a command-and-control (C2) relay that downloads and launches additional backdoor payloads. By serving as a dynamic dropper, the malware can keep lateral movement hidden within otherwise benign network traffic, making it difficult for defenders to pinpoint the original compromise. The ability to run both as an injected DLL and an autonomous executable increases its versatility across diverse system configurations. The combination of stealthy injection techniques and persistent payload delivery gives Proxysvc a substantial operational advantage. When left undetected, it can give attackers extended access to critical academic data, intellectual property, or infrastructure resources—making it a significant risk in environments that rely heavily on shared networks and research collaborations.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is moderate. The publicly available description confirms Proxysvc’s role as a Lazarus Group dropper in Operation GhostSecret, but it lacks detailed evidence on installation methods, persistence mechanisms, or specific command set. Additional technical analysis is required to fully map the malware’s lifecycle and validate threat behavior across target environments.
Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret. It has appeared to be operating undetected since 2017 and was mostly observed in higher education organizations. The goal of Proxysvc is to deliver additional payloads to the target and to maintain control for the attacker. It is in the form of a DLL that can also be executed as a standalone process. (Citation: McAfee GhostSecret)