ProCC logo

ProCC

0 incidentes 0 paises 0 sectores apt BR Ultimo: -
Ver en IntelTracker → APTTrail →
ProCC is an advanced persistent threat (APT) group with a suspected origin in Brazil, primarily motivated by cyber espionage and data theft. The group distinguishes itself through its consistent targeting of the hospitality sector and the use of email attachments to exploit specific vulnerabilities, notably CVE-2017-0199, to deploy custom Remote Access Trojans. ProCC's operational focus involves meticulous data collection, including information from clipboards and printer spoolers, and capturing screenshots on compromised systems.
Tecnicas MITRE
T1112 - Modify Registry, T1140 - Deobfuscate/Decode Files or Information, T1071.001, T1078.003, T1091 - Replication Through Removable Media, T1553.005 - Mark-of-the-Web Bypass

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Tipo
apt
Pais origen
BR
Motivacion
-
Impacto
32
Actualizado
Sat, 24 Fe

Sectores objetivo (SOCRadar)

Accommodation