Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: OilRig, a tagged union, sum type, employees at target organizations, PCPcat, ShellForce, DeadCatx3

Description

ProCC is a threat actor targeting the hospitality sector with remote access Trojan malware. They use email attachments to exploit vulnerabilities like CVE-2017-0199 and deploy customized versions of RATs such as RevengeRAT, NjRAT, NanoCoreRAT, and 888 RAT. ProCC's malware is capable of collecting data from the clipboard and printer spooler, as well as capturing screenshots on infected machines.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Information technology
Telecommunications
Healthcare
Manufacturing
Retail
Hospitality
Gaming
Media
Mining
Education
Critical infrastructure

Targeted Countries / Regions

US
IL
CN
DE
BR
IR

AI Analysis

· 1 week ago

Executive Summary

ProCC is a threat actor targeting the hospitality sector through remote access Trojan (RAT) malware deployment via malicious email attachments. Their campaigns exploit known vulnerabilities such as CVE-2017-0199 and deploy customized RATs like RevengeRAT, NjRAT, NanoCoreRAT, and 888 RAT. ProCC's activities focus on data collection from infected systems, posing significant risks to sensitive information in the hospitality industry.

Goals & Targeting

ProCC's strategic objectives appear to be centered around espionage and data theft, particularly targeting sectors where sensitive customer information is abundant. Their focus on the hospitality industry, which handles vast amounts of personally identifiable information (PII) and transactional data, aligns with their malware capabilities for data extraction. The threat actor likely targets countries with significant tourism industries, as hotels and travel agencies are key components of such economies.

Enhanced Description

ProCC is a cyber threat actor specialized in targeting the hospitality sector using remote access Trojans (RATs). Their primary method of infection involves sending email attachments containing malicious payloads that exploit vulnerabilities such as CVE-2017-0199. Once deployed, these RATs provide ProCC with unauthorized access to victim systems, enabling data collection activities including clipboard content, printer spooler data, and screenshot captures. This level of access allows the threat actor to gather sensitive information, potentially compromising guest data, financial records, and operational systems. The targeting of the hospitality sector suggests a focus on industries handling large volumes of personal information and may have varying levels of cybersecurity maturity.

Key Capabilities

  • Deployment of remote access Trojans (RATs)
  • Customization of RAT payloads
  • Exploitation of known vulnerabilities like CVE-2017-0199
  • Data collection from infected systems
  • Persistence and lateral movement within networks

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Initial Access
Execution
Defense Evasion

ATT&CK Techniques

T1566.003
T1059.003
T1047.001
T1284.001
T1003.001

Software / Tooling

RevengeRAT
NjRAT
NanoCoreRAT
888 RAT
Custom malwares for exploiting CVE-2017-0199

Campaigns & Victims

ProCC's campaigns are characterized by their use of email-based attacks and RAT implants. Their targeting patterns suggest a focus on sectors with weak cybersecurity defenses and rich data repositories, such as the hospitality industry. Campaign activity appears to be ongoing, with recent sightings indicating active development and deployment of new malware variants. Notable past operations include multiple breaches affecting hotels and related services globally.

IOC Patterns

  • Spear-phishing emails with malicious Office document attachments
  • Remote access Trojan (RAT) payloads targeting Windows systems
  • Exploitation of CVE-2017-0199 vulnerability
  • Clipboard data theft
  • Printer spooler activity manipulation
  • Screen capture activities on infected machines

Recommended Actions

  • Patch and mitigate known vulnerabilities like CVE-2017-0199
  • Monitor email channels for suspicious attachments, especially from unknown senders
  • Implement endpoint detection and response (EDR) solutions to detect RAT activity
  • Conduct regular user training on phishing awareness
  • Segregate network access for systems handling sensitive data
  • Use threat intelligence feeds to block known ProCC-related domains and IP addresses

Suggested Tags

APT
cyber_espionage
data_theft
hospitality_sector
malware_campaigns

Confidence Assessment

Low confidence in the accuracy of this assessment due to limited publicly available information on ProCC's origin, operational history, and specific campaigns. The data gaps include a lack of confirmed attributions or detailed attack patterns beyond malware usage.

ATT&CK Techniques

Command & Control
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 5 SHA-256 Hash 3 IPv4 Address 7 Domain 5

References

  1. attack.mitre.org — Cited by web research for: employees at target organizations
  2. unit42.paloaltonetworks.com — Cited by web research for: PCPcat
  3. attack.mitre.org — Cited by web research for: Interception
  4. unit42.paloaltonetworks.com — Cited by web research for: Symbiote

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

15

Tactics

Tags

Healthcare Targeting
Backdoor / C2
APT
cyber_espionage
data_theft
hospitality_sector
malware_campaigns

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.