Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Proxysvc

Proxysvc

TLP:CLEAR
Family

AI Analysis

· 21 hours ago

Executive Summary

Proxysvc is a Lazarus-derived DLL used stealthily since 2017 to deliver additional payloads into higher‑education systems. It functions both as an injected component and a standalone process, facilitating covert command-and-control channels. Its dual functionality allows attackers to maintain persistence while bypassing many conventional defense mechanisms, posing a serious risk to academic institutions.

Enhanced Description

Proxysvc is a clandestine Windows DLL that was employed by the North Korean Lazarus Group during its Operation GhostSecret campaign. First identified in 2017 targeting mainly higher‑education institutions, the module masquerades as legitimate software while functioning as both a loader and stand‑alone application. In DLL mode it is designed to be injected into trusted processes, allowing it to evade initial security scans by blending in with normal system activity. Once resident, Proxysvc acts primarily as a command-and-control (C2) relay that downloads and launches additional backdoor payloads. By serving as a dynamic dropper, the malware can keep lateral movement hidden within otherwise benign network traffic, making it difficult for defenders to pinpoint the original compromise. The ability to run both as an injected DLL and an autonomous executable increases its versatility across diverse system configurations. The combination of stealthy injection techniques and persistent payload delivery gives Proxysvc a substantial operational advantage. When left undetected, it can give attackers extended access to critical academic data, intellectual property, or infrastructure resources—making it a significant risk in environments that rely heavily on shared networks and research collaborations.

Key Capabilities

  • acts as a dropper for secondary malware
  • can be injected into legitimate Windows processes via DLL injection
  • may execute independently as a standalone process
  • establishes encrypted or obfuscated command‑and‑control channels
  • dynamically downloads additional payloads from remote servers

ATT&CK Techniques

T1055
T1105
T1059

Recommended Actions

  • Deploy endpoint detection solutions that flag unknown DLLs appearing in system32, SysWOW64, and temporary directories;
  • Set up monitoring for anomalous inbound/outbound network traffic originating from non‑trusted processes;
  • Implement application whitelisting to block execution of unapproved executable files; Whitelist only signed binaries in critical directories;
  • Patch known Windows vulnerabilities that could facilitate DLL hijacking or process injection;
  • Educate users at higher‑education institutions about suspicious email attachments and URLs that may host initial delivery vectors;

Suggested Tags

Lazarus Group
Operation GhostSecret
DLL-based loader
Higher‑education target
Command and Control
Backdoor

Confidence Assessment

Confidence is moderate. The publicly available description confirms Proxysvc’s role as a Lazarus Group dropper in Operation GhostSecret, but it lacks detailed evidence on installation methods, persistence mechanisms, or specific command set. Additional technical analysis is required to fully map the malware’s lifecycle and validate threat behavior across target environments.

Description

Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret. It has appeared to be operating undetected since 2017 and was mostly observed in higher education organizations. The goal of Proxysvc is to deliver additional payloads to the target and to maintain control for the attacker. It is in the form of a DLL that can also be executed as a standalone process. (Citation: McAfee GhostSecret)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.