1200KM / tool
PcShare — Attack Tool
PcShare is an open source remote access tool that has been modified and used by Chinese threat actors, most notably during the FunnyDream campaign since late 2018.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: PcShare
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT5 · G1023 · Pinned relationship source (relationship--44fd01db-6dc1-4d7c-92e3-52a0af9f54f8)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1005 · Data from Local System · Detection rules & anomalies
- T1012 · Query Registry · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1027.013 · Encrypted/Encoded File · Detection rules & anomalies
- T1027.015 · Compression · Detection rules & anomalies
- T1036.001 · Invalid Code Signature · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1140 · Deobfuscate/Decode Files or Information · Detection rules & anomalies
- T1218.011 · Rundll32 · Detection rules & anomalies
- T1546.015 · Component Object Model Hijacking · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Deletion · DC0040
- File Metadata · DC0059
- File Modification · DC0061
- Firmware Modification · DC0004
- Image Metadata · DC0028
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Scheduled Job Creation · DC0001
- Script Execution · DC0029
- Service Creation · DC0060
- Service Metadata · DC0041
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.