Last seven days
- First activity
- Aug 24, 2026
- Last activity
- Aug 24, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
FlawedGrace, also known as GraceWire, is a Windows remote access trojan and backdoor written in C++ that has been active since at least 2017.
Profile source: Mallory opens in a new tabFlawedGrace
FlawedGrace, also known as GraceWire, is a Windows remote access trojan and backdoor written in C++ that has been active since at least 2017. It is a full-featured post-compromise implant associated most closely with the financially motivated TA505 cluster and has also appeared in operations linked to Evil Corp and in intrusion chains involving TrueBot. FlawedGrace has been used as a second-stage payload following loaders and downloaders such as ServHelper, Get2, MirrorBlast, KiXtart- and REBOL-based intermediaries, and TrueBot, and it has also been observed in intrusions that later culminated in enterprise ransomware deployment, including Clop-related activity.
The malware provides hands-on remote control of infected systems and supports standard RAT functionality including command execution, file transfer, script execution, and remote desktop-related capabilities. Public reporting also describes password-stealing functionality, process injection into legitimate Windows processes, encrypted payload storage, and persistence mechanisms including scheduled-task abuse and registry-based storage. In some observed activity, operators abused a legitimate backup-related scheduled task and its COM handler to load FlawedGrace for persistence. Government reporting has additionally described registry modification, use of print-spooler-related components for persistence or privilege escalation, and injection into system processes to establish command-and-control connectivity.
FlawedGrace uses an encrypted custom binary command-and-control protocol, commonly over TCP port 443, and stores configuration data in encrypted form. Reverse-engineering reporting has characterized its networking stack as sophisticated and noted use of a custom virtual filesystem for configuration management and command-and-control operations. Later variants introduced stronger obfuscation, including encrypted strings, obfuscated API resolution, and encrypted configuration storage in resources, memory, and the registry.
Distribution has most often been tied to phishing-driven intrusion chains. TA505 campaigns delivered precursor malware through malicious Office documents, macro-enabled Excel attachments, HTML redirectors, landing pages impersonating file-sharing services, and related social-engineering lures. Those initial stages then retrieved intermediate loaders or downloaders that ultimately deployed FlawedGrace. It has also been observed after exploitation-based access, including activity involving Netwrix Auditor and SolarWinds Serv-U compromises, as well as in campaigns where Raspberry Robin or TrueBot served as upstream delivery mechanisms.
FlawedGrace has been used against a broad range of sectors rather than a single niche. Reported targeting associated with its operators includes financial institutions, retail, restaurants, healthcare, education, government, and other enterprise environments across multiple regions. Its role in these operations is typically as a durable foothold and operator-controlled backdoor that enables deeper compromise, follow-on tooling, credential theft, lateral movement, and preparation for monetization through ransomware or other financially motivated objectives.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
https://www.proofpoint.com/us/threat-insight/post/servhelper-and-flawedgrace-new-malware-introduced-ta505
Researchers thought EvilCorp to be linked to TrueBot due to TrueBot dropping FlawedGrace. FlawedGrace is malware that is attributed to EvilCorp.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.