Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 03:26:01 UTC Home > List all groups > List all tools > List all groups using tool Proxysvc Tool: Proxysvc Names Proxysvc Category Malware Type Backdoor, Tunneling Description Proxysvc is a malicious DLL used by Lazarus Group in a campaign known as Operation GhostSecret. It has appeared to be operating undetected since 2017 and was mostly observed in higher education organizations. The goal of Proxysvc is to deliver additional payloads to the target and to maintain control for the attacker. It is in the form of a DLL that can also be executed as a standalone process. Information MITRE ATT&CK AlienVault OTX Last change to this tool card: 22 April 2020 Download this tool card in JSON format All groups using tool Proxysvc Changed Name Country Observed APT groups Lazarus Group, Hidden Cobra, Labyrinth Chollima 2007-May 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=cd3b29aa-2cf0-4710-bcbc-8794c624e2a7 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=cd3b29aa-2cf0-4710-bcbc-8794c624e2a7 Page 1 of 1