CrackMapExec is an open-source, dual-use post-exploitation tool used for network assessment and abused by threat actors for reconnaissance, credential access, and lateral movement in Windows and Active Directory environments. It is not inherently a malware family. Its discovery capabilities include identifying active hosts and machine names, collecting DNS information, enumerating domain user accounts, and listing network shares and their associated permissions.
CrackMapExec supports remote command execution through Windows Management Instrumentation, including execution of PowerShell commands. It can extract password hashes from Local Security Authority secrets and modify WDigest-related registry settings to facilitate credential access. It also supports password spraying by attempting authentication with a supplied list of usernames and a single password. These capabilities allow operators to map compromised networks, obtain credentials, and execute commands on additional systems.
Documented adversary users include MuddyWater, APT39, Dragonfly, and Twelve. CrackMapExec has also been used in post-compromise activity following exploitation of Ivanti Connect Secure appliances. An obfuscated version was deployed during an intrusion at a utility company in Laos. Its use spans multiple intrusion sets and does not independently establish attribution to a particular actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In addition to this, an obfuscated version of the publicly available CrackMapExec tool appeared to be deployed.
Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
CrackMapExec can execute PowerShell commands via WMI.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Here, we will use Crackmapexec and check if an already obtained credential can authenticate on other machines on the domain.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
The content uses Meterpreter `hashdump`, Mimikatz `lsadump::sam`, Impacket `secretsdump.py`, and CrackMapExec `--sam` to obtain credentials.
`hashdump` extracts local user password hashes from the SAM database; Mimikatz is invoked with `lsadump::sam`.
The threat actor used password-cracking techniques to obtain the plaintext passwords from obtained credential hashes. The threat actor dropped and executed open-source and free password cracking tools such as Hydra, SecretsDump, and CrackMapExec, and Python.
I used the username list TryHackMe kindly provided us back in Task 3 and threw the password found in Task 4 at it. crackmapexec smb 192.168.12.100 -u ... -p 'MegaCorp01!' ... #Alternate TTP is to password spray with kerbrute
During Operation Wocao, the threat actors enabled Wdigest by changing the HKLM\SYSTEM\ControlSet001\Control\SecurityProviders\WDigest registry value from 0 (disabled) to 1 (enabled). Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest ... to force credentials to be stored in clear text in memory.
Example Attack Scenario: NTLM Relay Attack ... Responder used to carry out a poisoning attack against LLMNR, NBT-NS, and mDNS traffic, along with capturing authentication hashes. NTLMrelayX is then used to relay those authentication hashes to the list of relay targets.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Internal SMB brute and scan across 192[.]168[.]0[.]0/24... Advanced IP Scanner run.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Threat actors also deploy tools like Mimikatz, CrackMapExec, and Rclone to harvest network secrets and stage bulk file exfiltration
Example Attack Scenario: NTLM Relay Attack ... Responder used to carry out a poisoning attack against LLMNR, NBT-NS, and mDNS traffic, along with capturing authentication hashes. NTLMrelayX is then used to relay those authentication hashes to the list of relay targets.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A post-exploitation and network-enumeration tool referenced as matching host-operation and task-discovery activity in the intrusion.
Post-exploitation tool for enumerating and moving laterally in Windows/AD environments using SMB/WinRM and credential reuse.
Post-exploitation tool that can enumerate shared folders and associated permissions across a targeted network.
Post-exploitation framework used for credential access and lateral movement; here used (via lsassy) to dump LSASS memory remotely (comsvcs.dll MiniDump and WER/Out-Minidump techniques).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.