PsExec is a legitimate Microsoft Sysinternals remote administration utility that is frequently abused by threat actors for remote command execution and lateral movement in Windows environments. It operates by copying a service component to a remote host over administrative SMB shares, installing and starting a temporary Windows service, and launching commands under specified credentials or as NT AUTHORITY\SYSTEM. Because it is a signed and widely used administrative tool, PsExec commonly appears in ransomware, intrusion, and post-exploitation playbooks as a living-off-the-land mechanism rather than as malware in the conventional sense.
In adversary operations, PsExec is routinely used after credential theft or session compromise to execute payloads on additional systems, deploy ransomware, run reconnaissance commands, and expand access across Active Directory domains. Multiple ransomware ecosystems and intrusion sets have used PsExec alongside tools such as Mimikatz, Impacket, Cobalt Strike, and WMI. Reported use cases include propagation of ransomware binaries, execution of commands on servers and workstations, and privilege elevation to SYSTEM through the utility’s service-based execution model. Threat actors have also embedded or dropped copies of PsExec within broader malware toolchains to support automated spreading.
PsExec primarily targets Windows systems and is especially relevant in enterprise networks where administrative shares and remote service creation are permitted. Its abuse is strongly associated with lateral movement, post-exploitation activity, and service-based remote execution. Although PsExec itself is not inherently malicious and is widely used by administrators, its presence in intrusion chains is a high-value indicator of hands-on-keyboard activity, ransomware staging, or remote execution across compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
37 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Additionally, they employ PsExec to remotely execute the ransomware binary on targeted systems, providing an alternative method for spreading the infection when the GPO-based approach is not feasible.
Microsoft also observed the use of PsExec and Impacket for lateral movement and the use of Group Policy Objects (GPO) to deploy the Warlock payload.
Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.
GOLD SALEM has been observed using PsExec and Impacket (WMI) for lateral movement within compromised environments.
"...publicly available utilities like PsExec, to move laterally within compromised networks."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers also relied on PsExec, Microsoft's remote administration utility, to move laterally across the victim's network.
the attackers shifted their tactics to using PsExec as their primary mass deployment vector
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote execution utility abused by the operator to obtain SYSTEM shells on local hosts during post-compromise operations.
Легитимный инструмент удалённого администрирования, используемый для lateral movement через SMB/Admin$ и запуска полезной нагрузки на удалённых системах; в тексте прямо указан как основной инструмент распространения ransomware у ряда групп.
PsExec is used for lateral movement and remote command execution, including obtaining a shell on the domain controller after pass-the-hash authentication.
PsExec is used by the operators as a lateral movement and remote execution utility to spread the ransomware across active domain systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.