RemoteExec is a PsExec-like remote execution tool used by APT15, also known as Ke3chang, to remotely execute batch scripts and binaries on Windows systems. In NCC Group’s investigation of a May 2017 compromise of a UK Government services provider attributed to APT15, the tool was observed as part of the actor’s lateral movement and "living off the land" tradecraft. The attackers used administrative shares such as C$ and RemoteExec to move within the victim environment and execute payloads on remote hosts. The broader intrusion involved theft of sensitive documents assessed to relate to UK government departments and military technology. The content directly associates RemoteExec with APT15/Ke3chang and describes it specifically as similar to Microsoft PsExec; no standalone malware persistence, command-and-control, or unique indicators of compromise for RemoteExec itself are provided in the source content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT15 then used a tool known as RemoteExec (similar to Microsoft’s Psexec) in order to remotely execute batch scripts and binaries.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote execution utility (PsExec-like) used for lateral movement/remote command execution of batch scripts and binaries across hosts.
PsExec-like remote execution utility used for lateral movement/remote command execution of batch scripts and binaries across hosts.
Remote execution tool (PsExec-like) used to run scripts/binaries on remote systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.