Skip to main content
Mallory
MalwareRansomwareUsed by 2 actors

PCHunter

PCHunter is a post-compromise utility observed in multiple ransomware and intrusion contexts as part of attacker toolsets used to disable or tamper with security protections. The provided reporting places it alongside tools such as HRSword, GMER, YDark, WKTools, DumpGuard, StpProcessMonitor BYOVD, and PowerTool, with several of these utilities abusing vulnerable kernel drivers to terminate endpoint protection processes. Symantec reported Trigona ransomware affiliates using PCHunter before deploying a custom exfiltration tool, in conjunction with AnyDesk for remote access, PowerRun for elevated execution, and Mimikatz and Nirsoft utilities for credential theft. Mandiant also observed UNC2447 using PCHUNTER during recon and exfiltration activity alongside ADFIND, BLOODHOUND, MIMIKATZ, RCLONE, ROUTERSCAN, S3BROWSER, ZAP, and 7ZIP. Separately, CTU researchers observed PCHunter deployed in Qilin-related intrusions after RDP-based initial access and lateral movement, possibly to disable antivirus software, with associated activity including memory dumping and shadow copy deletion prior to ransomware deployment. High-confidence context from the content indicates PCHunter is used on Windows systems as a defense-evasion or security-disabling tool in ransomware and financially motivated intrusion operations, including activity linked to Trigona, UNC2447, and Qilin/GOLD FEATHER.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Qilin

CTU researchers have observed remote desktop protocol (RDP) abused for initial access and lateral movement before the post-compromise PCHunter and PowerTool tools were deployed, possibly with the intention of disabling antivirus software.

via secureworks threat profilessecureworks.com
UNC2447

...UNC2447 has been observed using the following tools: ... PCHUNTER ...

via mandiant threat intelligencecloud.google.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

T1068Exploitation for Privilege EscalationEvidence2

A toolkit including PCHunter, Gmer, YDark, WKTools, DumpGuard and StpProcessMonitorByovd was used in the security killing process, which included bring your own vulnerable driver (BYOVD) techniques.

Stealth

1 technique
T1211Exploitation for Defense EvasionEvidence2
TacticStealth

Before deploying the custom uploader, attackers disable security tools using multiple utilities, including HRSword, PCHunter, and GMER, often abusing vulnerable kernel drivers to kill protections.

Other

2 techniques
T1562Impair DefensesEvidence4

Before deploying the custom uploader, attackers disable security tools using multiple utilities, including HRSword, PCHunter, and GMER, often abusing vulnerable kernel drivers to kill protections.

T1562.001Disable or Modify ToolsEvidence1

Many of these leveraged vulnerable kernel drivers to terminate endpoint protection processes. PowerRun was used to execute some of these tools with elevated privileges.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.