Skip to main content
Mallory
MalwareRansomwareUsed by 2 actorsExploits 1 CVE

DWAgent

DWAgent is a legitimate remote administration tool that threat actors have deployed post-compromise to maintain persistent remote access to victim systems and to facilitate follow-on activity. In the provided reporting, it is repeatedly used alongside other dual-use and offensive tooling such as AnyDesk, Earthworm, SharpHound, Impacket, Rubeus, Certipy, and GoExec. Observed use cases include maintaining access to compromised endpoints, deploying additional payloads, supporting Active Directory reconnaissance, and enabling broader post-exploitation operations.

DWAgent appears in multiple intrusion clusters. Rapid7 reported MuddyWater/Seedworm, an Iranian MOIS-affiliated actor, using DWAgent and in at least one case AnyDesk after Microsoft Teams-based social engineering, credential harvesting, and MFA manipulation. In that intrusion, persistence involved RDP plus a DWAgent installation chain including dwagent.exe, pythonw.exe, dwagsvc.exe, and dwaglnc.exe. Cisco Talos and related reporting also describe China-linked UAT-8837 using DWAgent after initial access obtained via compromised credentials or exploitation of vulnerable servers, including Sitecore CVE-2025-53690. In those cases, DWAgent was used as a remote administration tool for persistence, remote control, and deployment of additional malware; one report specifically states it was installed as a SYSTEM service.

Targeting described in the content includes critical infrastructure organizations in North America and internet-exposed Sitecore environments. In Sitecore exploitation campaigns tied to CVE-2025-53690, DWAgent was deployed after successful authentication bypass and remote code execution via malicious ViewState payloads on endpoints such as /sitecore/blocked.aspx. Associated post-exploitation activity included creation of unauthorized administrator accounts, credential dumping, theft of web.config and registry hives, network tunneling with Earthworm, reconnaissance with WeepSteel and SharpHound, data staging with 7-Zip, and exfiltration.

High-confidence indicators directly mentioned for DWAgent include the filenames/processes dwagent.exe, pythonw.exe, dwagsvc.exe, and dwaglnc.exe, as well as unexpected DWAgent service installation or execution on compromised hosts.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-53690Sitecore ViewState deserialization RCE via exposed sample machineKeyExploited in the wild

On September 3, 2025, a critical zero-day vulnerability (CVE-2025-53690) in the Sitecore Experience Platform sent shockwaves through the enterprise content management community. Exploited in-the-wild, this flaw allowed remote attackers to gain full control of vulnerable sites through ViewState deserialization attacks... Attackers were able to exploit this weakness, crafting malicious payloads that allowed them to execute arbitrary code on impacted servers.

via cyberthronethecyberthrone.in
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
MuddyWater

From there, the TA established persistence using remote access tools such as DWAgent and AnyDesk, before deploying additional payloads and further control of the environment.

via rapid7 blograpid7.com
UAT-8837

DWAgent, to enable persistent remote access and Active Directory reconnaissance

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1133External Remote ServicesEvidence1

The intrusion Rapid7 examined started through Microsoft Teams social engineering... and, in some cases, deployed AnyDesk for remote access.

T1190Exploit Public-Facing ApplicationEvidence1

Initial Access: The attacker targets Sitecore installations exposed to the internet, specifically those running with factory-default or sample machine keys.

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1
TacticExecution

By submitting specially crafted POST requests (e.g., to /sitecore/blocked.aspx), attackers achieved remote code execution (RCE).

T1203Exploitation for Client ExecutionEvidence1
TacticExecution

Exploited in-the-wild, this flaw allowed remote attackers to gain full control of vulnerable sites through ViewState deserialization attacks

Persistence

3 techniques
T1133External Remote ServicesEvidence1

The intrusion Rapid7 examined started through Microsoft Teams social engineering... and, in some cases, deployed AnyDesk for remote access.

T1543Create or Modify System ProcessEvidence1

The DWAgent installation chain included: dwagent.exe ... dwagsvc.exe DWAgent service

T1543.003Windows ServiceEvidence1

If the token is elevated, a service named CacheDB is created...

T1543Create or Modify System ProcessEvidence1

The DWAgent installation chain included: dwagent.exe ... dwagsvc.exe DWAgent service

T1543.003Windows ServiceEvidence1

If the token is elevated, a service named CacheDB is created...

Discovery

1 technique
T1018Remote System DiscoveryEvidence1
TacticDiscovery

Some of the notable tools include ... DWAgent, to enable persistent remote access and Active Directory reconnaissance SharpHound, to collect Active Directory information ... Certipy, a tool for Active Directory discovery and abuse

Lateral Movement

2 techniques
T1021Remote ServicesEvidence2

This included EARTHWORM for creating secret tunnels, DWAGENT for remote access, and SHARPHOUND for mapping the network.

T1021.001Remote Desktop ProtocolEvidence1

After establishing initial access, the threat actors utilized RDP sessions and DWAgent, another remote management tool, to maintain persistence.

T1105Ingress Tool TransferEvidence2

the threat actors downloaded and installed WinRAR... In one case, the actors installed both WinRAR and Google Chrome... Sophos observed the Akira actors dropping a bespoke Trojan

T1219Remote Access ToolsEvidence8

Specifically, Kimsuky leveraged legitimate VS Code tunneling mechanisms to establish persistence and distributed the open-source DWAgent remote monitoring and management tool for post-exploitation activities.

Impact

1 technique
T1499.004Application or System ExploitationEvidence1
TacticImpact

Sitecore, widely used by Fortune 500 companies and large organizations, was found to have a major flaw in its handling of ASP.NET ViewState when default or sample machine keys were present.

INDICATORS OF COMPROMISE

IOCs tracked for this family

6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
domain●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching6

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.