Pcexter is an uploader that has been used by ToddyCat since at least 2023 to exfiltrate stolen files.[1]

ID: S1102
Platforms: Windows
Version: 1.0
Created: 22 January 2024
Last Modified: 22 January 2024

Techniques Used

Domain ID Name Use
Enterprise T1005 Data from Local System

Pcexter can upload files from targeted systems.[1]

Enterprise T1567 .002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Pcexter can upload stolen files to OneDrive storage accounts via HTTP POST.[1]

Enterprise T1083 File and Directory Discovery

Pcexter has the ability to search for files in specified directories.[1]

Enterprise T1574 .002 Hijack Execution Flow: DLL Side-Loading

Pcexter has been distributed and executed as a DLL file named Vspmsg.dll via DLL side-loading.[1]

Groups That Use This Software

ID Name References
G1022 ToddyCat