RAT

Parsec

Parsec is a remote desktop streaming tool for remote access and monitoring, mainly used for gaming and collaboration. Remote desktop reimagined – a seamless 4k experience at up to 60 frames per second with near-zero latency. Secure, flexible, effortless access to whatever you do, at any time, from wherever you go. Parsec focuses on real-time graphical interaction rather than system administration but can still be abused for lateral movement and initial access.

Tool overview

Category
RAT
Research authors
Luca Di Bartolomeo & Matt Green
Created
2025-03-16
Last modified
2025-03-16
Privileges
Current User
Free / availability
Yes
Verification required
No
Supported platforms
AndroidLinuxWindowsmacOS

Capabilities

Remote ControlGUI Support

Executables & installation paths

Filename
parsecd.exe
OriginalFileName
Not recorded
Description
Parsec
Product
Parsec

Installation paths

C:\Program Files\Parsec\*
parsecd.exe
pservice.exe

Code signing

signer name
Unity Technologies SF
certificate thumbprint
B73664F2AF5A8EF4529F03DB4B2CCD8275A6EC91
src file sha256
cc62d22bf8a082621fa25fdeee3150c17b09dbc09c9371e3dcdd6ec83967770c
src file path
downloaded_files/parsec/cc62d22bf8a082621fa25fdeee3150c17b09dbc09c9371e3dcdd6ec83967770c
src file company
Parsec

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files\Parsec\parsecd.exe
Description
Main parsec executable
OS
Windows
Example
  • SHA256: 38011E713B4BE8577576062754CAD03E9899859488932AE4C9C83E5FBB5CB7D2
File
C:\Program Files\Parsec\pservice.exe
Description
Background service managing input devices
OS
Windows
Example
  • SHA256: CC62D22BF8A082621FA25FDEEE3150C17B09DBC09C9371E3DCDD6EC83967770C
File
C:\Program Files\Parsec\teams.exe
Description
Parsec for teams collaboration and user session management
OS
Windows
Example
  • SHA256: 6DC71B2E92B770DCFECA4A32C8F1787210311F731F1124754DF193EC22D5D13E

FORENSIC EVIDENCE

Event log artifacts

EventID
7045
ProviderName
Service Control Manager
LogFile
System.evtx
ServiceName
parsecvirtualds
ImagePath
"\SystemRoot\System32\drivers\parsecvirtualds.sys"
ServiceType
kernel mode driver
StartType
demand start
AccountName
System
Description
Parsec service installation event
Example
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"><System><Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}"EventSourceName="Service Control Manager" /><EventID Qualifiers="16384">7045</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated SystemTime="2025-03-16T23:16:53.5897766Z" /><EventRecordID>596</EventRecordID><Correlation /><Execution ProcessID="804" ThreadID="912" /><Channel>System</Channel><Computer>Computer</Computer><Security UserID="S-1-5-18" /></System><EventData><Data Name="ServiceName">parsecvirtualds</Data><Data Name="ImagePath">\SystemRoot\System32\drivers\parsecvirtualds.sys</Data><Data Name="ServiceType">kernel mode driver</Data><Data Name="StartType">demand start</Data><Data Name="AccountName"></Data></EventData></Event>

FORENSIC EVIDENCE

Network artifacts

Description
Known domains used by Parsec
Domains
  • parsec.app
  • parsec.gg
  • *.parsec.app
Ports
  • 443
  • 3478

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/parsec_network_sigma.yml
Description
Detects potential network activity of Parsec RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/parsec_files_sigma.yml
Description
Detects potential files activity of Parsec RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/parsec_processes_sigma.yml
Description
Detects potential processes activity of Parsec RMM tool

References

Acknowledgements

Person
Luca Di Bartolomeo
Handle
@LucaInfoSec
Person
Matt Green
Handle
@mgreen27