xCmd is a malware/tooling family that can execute binaries on remote Windows systems by creating and starting a service. The provided content specifically identifies this as remote execution via Windows service creation, consistent with Service Control Manager-style execution used for lateral movement or remote payload deployment. No additional high-confidence details on infection vector, persistence, targeted industries, associated threat actor, or indicators of compromise are provided in the content beyond this capability.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"Anchor can create and execute services to load its payload"; "APT32's backdoor has used Windows services as a way to execute its malicious payload"; "Ragnar Locker has used sc.exe to execute a service that it creates"; "Shamoon creates a new service named 'ntssrv' to execute the payload"
"PsExec ... can be used to execute binaries on remote systems using a temporary Windows service"; "RemoteCMD can execute commands remotely by creating a new service on the remote system"; "Winexe installs a service on the remote system, executes the command, then uninstalls the service"
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote execution tool/malware that executes binaries on remote systems by creating and starting a Windows service.
Remote execution tool that runs binaries on remote systems by creating/starting a Windows service.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.