Skip to content

FlawedGrace

FlawedGrace, also known as GraceWire, is a Windows remote access trojan and backdoor written in C++ that has been active since at least 2017.

Profile source: Mallory opens in a new tab

FlawedGrace

Family profile

FlawedGrace, also known as GraceWire, is a Windows remote access trojan and backdoor written in C++ that has been active since at least 2017. It is a full-featured post-compromise implant associated most closely with the financially motivated TA505 cluster and has also appeared in operations linked to Evil Corp and in intrusion chains involving TrueBot. FlawedGrace has been used as a second-stage payload following loaders and downloaders such as ServHelper, Get2, MirrorBlast, KiXtart- and REBOL-based intermediaries, and TrueBot, and it has also been observed in intrusions that later culminated in enterprise ransomware deployment, including Clop-related activity.

The malware provides hands-on remote control of infected systems and supports standard RAT functionality including command execution, file transfer, script execution, and remote desktop-related capabilities. Public reporting also describes password-stealing functionality, process injection into legitimate Windows processes, encrypted payload storage, and persistence mechanisms including scheduled-task abuse and registry-based storage. In some observed activity, operators abused a legitimate backup-related scheduled task and its COM handler to load FlawedGrace for persistence. Government reporting has additionally described registry modification, use of print-spooler-related components for persistence or privilege escalation, and injection into system processes to establish command-and-control connectivity.

FlawedGrace uses an encrypted custom binary command-and-control protocol, commonly over TCP port 443, and stores configuration data in encrypted form. Reverse-engineering reporting has characterized its networking stack as sophisticated and noted use of a custom virtual filesystem for configuration management and command-and-control operations. Later variants introduced stronger obfuscation, including encrypted strings, obfuscated API resolution, and encrypted configuration storage in resources, memory, and the registry.

Distribution has most often been tied to phishing-driven intrusion chains. TA505 campaigns delivered precursor malware through malicious Office documents, macro-enabled Excel attachments, HTML redirectors, landing pages impersonating file-sharing services, and related social-engineering lures. Those initial stages then retrieved intermediate loaders or downloaders that ultimately deployed FlawedGrace. It has also been observed after exploitation-based access, including activity involving Netwrix Auditor and SolarWinds Serv-U compromises, as well as in campaigns where Raspberry Robin or TrueBot served as upstream delivery mechanisms.

FlawedGrace has been used against a broad range of sectors rather than a single niche. Reported targeting associated with its operators includes financial institutions, retail, restaurants, healthcare, education, government, and other enterprise environments across multiple regions. Its role in these operations is typically as a durable foothold and operator-controlled backdoor that enables deeper compromise, follow-on tooling, credential theft, lateral movement, and preparation for monetization through ransomware or other financially motivated objectives.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 24, 2026
Last activity
Aug 24, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • MD1

Leading providers

  • MivoCloud SRL1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
TA505

https://www.proofpoint.com/us/threat-insight/post/servhelper-and-flawedgrace-new-malware-introduced-ta505

INDRIK SPIDER

Researchers thought EvilCorp to be linked to TrueBot due to TrueBot dropping FlawedGrace. FlawedGrace is malware that is attributed to EvilCorp.

Exploited software

Vulnerabilities linked to FlawedGrace

1 CVEs

MITRE ATT&CK

FlawedGrace in ATT&CK

25 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.