PCShare Backdoor
PCShare is open-source backdoor trojan available on a number of primarily Chinese-language hacking forums.
Summary
PCShare is open-source backdoor trojan available on a number of primarily Chinese-language hacking forums.
Affected platforms
The following platforms are known to be affected:
Threat details
Unlike most backdoors, PCShare uses a custom loader that differs with each individual campaign. This loader is disguised within spoofed versions of legitimate applications, typically graphical and firmware drivers, hosted through third-party sites. When downloaded and executed, the loader uses DLL side-loading to inject PCShare into the memory of a number of running processes, ensuring it evades anti-virus detection.
Once installed, PCShare will connect to a command and control sever using details passed to it by the loader in a number of remote files. If successful, PCShare will then download and install any payloads from the C2 server.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:54 pm