WMIExec is a utility used for remote command execution over Windows Management Instrumentation (WMI), commonly observed as a lateral movement tool rather than a standalone malware family. In the provided content, APT41 used WMIEXEC to execute whoami commands on remote machines, and a separate campaign targeting South Korean web servers used WMIExec alongside Ladon after credential theft to move laterally. That campaign involved exploitation of file upload vulnerabilities to deploy ASP/ASPX web shells on Windows IIS servers, use of reconnaissance tooling such as Fscan, credential dumping with Network Password Dump, and lateral movement via WMIExec using the NT hash of an administrator account. The same activity also targeted Linux systems with additional tooling including MeshAgent, SuperShell, and WogRAT, but WMIExec specifically was associated with Windows-side remote execution and post-compromise movement. High-confidence context from the content indicates WMIExec is used by threat actors during post-exploitation to run commands on remote hosts, including identity-discovery commands such as whoami, often after successful credential theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT41 used the WMIEXEC utility to execute whoami commands on remote machines.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
"Block process creations originating from PsExec and WMI commands ... to prevent lateral movement originating from PsExec and WMI, including Impacket’s WMIexec."
It was followed by the execution of discovery commands using wmiexec in the context of the built-in domain administrator account.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WMIExec is a tool for executing commands remotely on Windows systems via WMI, commonly used for lateral movement within networks.
Remote execution/lateral movement utility leveraging WMI; here used to run discovery commands (whoami) on remote hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.