Also known as: OilRig, a tagged union, sum type, employees at target organizations, PCPcat, ShellForce, DeadCatx3
ProCC is a threat actor targeting the hospitality sector with remote access Trojan malware. They use email attachments to exploit vulnerabilities like CVE-2017-0199 and deploy customized versions of RATs such as RevengeRAT, NjRAT, NanoCoreRAT, and 888 RAT. ProCC's malware is capable of collecting data from the clipboard and printer spooler, as well as capturing screenshots on infected machines.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
ProCC is a threat actor targeting the hospitality sector through remote access Trojan (RAT) malware deployment via malicious email attachments. Their campaigns exploit known vulnerabilities such as CVE-2017-0199 and deploy customized RATs like RevengeRAT, NjRAT, NanoCoreRAT, and 888 RAT. ProCC's activities focus on data collection from infected systems, posing significant risks to sensitive information in the hospitality industry.
Goals & Targeting
ProCC's strategic objectives appear to be centered around espionage and data theft, particularly targeting sectors where sensitive customer information is abundant. Their focus on the hospitality industry, which handles vast amounts of personally identifiable information (PII) and transactional data, aligns with their malware capabilities for data extraction. The threat actor likely targets countries with significant tourism industries, as hotels and travel agencies are key components of such economies.
Enhanced Description
ProCC is a cyber threat actor specialized in targeting the hospitality sector using remote access Trojans (RATs). Their primary method of infection involves sending email attachments containing malicious payloads that exploit vulnerabilities such as CVE-2017-0199. Once deployed, these RATs provide ProCC with unauthorized access to victim systems, enabling data collection activities including clipboard content, printer spooler data, and screenshot captures. This level of access allows the threat actor to gather sensitive information, potentially compromising guest data, financial records, and operational systems. The targeting of the hospitality sector suggests a focus on industries handling large volumes of personal information and may have varying levels of cybersecurity maturity.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
ProCC's campaigns are characterized by their use of email-based attacks and RAT implants. Their targeting patterns suggest a focus on sectors with weak cybersecurity defenses and rich data repositories, such as the hospitality industry. Campaign activity appears to be ongoing, with recent sightings indicating active development and deployment of new malware variants. Notable past operations include multiple breaches affecting hotels and related services globally.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in the accuracy of this assessment due to limited publicly available information on ProCC's origin, operational history, and specific campaigns. The data gaps include a lack of confirmed attributions or detailed attack patterns beyond malware usage.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
15
Tactics