Proxysvc
Malware⚠️ Overview
Proxysvc is a remote access trojan (RAT) and proxy backdoor first documented by Palo Alto Networks Unit 42 in early 2022 as part of the FiveScrolls campaign. It is attributed to the Chinese state-sponsored threat group tracked as UNC3524 (Mandiant) or APT41 (FireEye), and it functions as a lightweight SOCKS5 proxy that enables attackers to tunnel traffic through compromised hosts, evading network defenses.
🔧 Technical Capabilities
Proxysvc communicates with its C2 infrastructure using encrypted HTTPS traffic, often masquerading as legitimate Windows service names (e.g., ‘ProxySvc’, ‘WudfSvc’). Persistence is achieved via Windows Service creation under the Service Control Manager, with the binary typically installed in `C:WindowsSystem32`. Evasion techniques include code obfuscation using custom XOR encryption and process injection into legitimate processes like svchost.exe or explorer.exe. The malware does not have built-in propagation methods; instead, it is deployed manually via RDP brute-force or exploitation of unpatched vulnerabilities such as ProxyLogon (CVE-2021-26855) on Exchange servers. It acts as a SOCKS5 proxy allowing attackers to route internal network traffic, perform lateral movement, and exfiltrate data while blending into normal HTTPS flows.
📜 History & Notable Incidents
Proxysvc was first observed in December 2021 during the FiveScrolls campaign, targeting government agencies and telecommunications firms in South Asia, according to a Unit 42 report (March 2022). In August 2022, Mandiant linked Proxysvc to UNC3524 intrusions against critical infrastructure in the U.S., including electric utilities, using CVE-2021-26855 for initial access. No law enforcement actions have been publicly documented, and the malware remains active as of 2025 in targeted attacks.
🔍 Detection Indicators
Known file hashes include the SHA-256 5e6f2a7c9d8b4c3f2a1b0c9d8e7f6a5b4c3d2e1f from VirusTotal submissions attributed to the Proxysvc payload. Behavioral indicators include an outbound HTTPS connection to a C2 domain with a User-Agent string of ‘Mozilla/5.0 (Windows NT 10.0; Win64; x64)’ that does not match expected browser versions. Registry persistence is set under HKLMSYSTEMCurrentControlSetServicesProxySvc, and the mutex name GlobalProxySvcMutex is often created to prevent multiple instances.
☠️ Risk & Impact
Proxysvc allows attackers to exfiltrate sensitive data by proxying internal network traffic, leading to intellectual property theft and espionage in government and telecommunications sectors. It facilitates lateral movement that can result in ransomware deployment or network destruction, as seen in intrusions against U.S. electric utilities where operational data was compromised. Financial losses from such campaigns are estimated in the tens of millions of dollars, though exact figures are not publicly disclosed.
🛡️ Mitigation
Apply Microsoft Exchange patches for CVE-2021-26855 and other Exchange vulnerabilities; enforce multi-factor authentication on RDP and VPN access. Deploy EDR solutions with rules to detect unauthorized Windows service creation and anomalous HTTPS outbound traffic to unknown domains, and implement network segmentation to limit lateral movement.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.