Attackers are abusing Microsoft Volume Shadow Copy Service (VSS) to impair recovery ahead of ransomware deployment and to access copied NTDS.dIT data containing Active Directory credentials. In a Huntress investigation, PsExec-launched SYSTEM shells on a domain controller were followed by RDP-session enumeration, creation of VSS shadow copies, and an attempted deletion of the newly created copies; endpoint antivirus blocked the deletion attempt.
The activity also included DNS enumeration and reconnaissance against another host, supporting an assessment of lateral movement and credential-access operations. VSS creation or deletion alone is not a reliable alert because backup, RMM, and administrative products commonly use the service; defenders should correlate VSS events with process lineage, privileged remote execution, reconnaissance, credential harvesting, and event timing.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Several minutes after creating the shadow copies, the actor attempted to delete them. Endpoint antivirus blocked and flagged the deletion attempt.
DNS enumeration and reconnaissance against at least one additional host occurred in the same activity window, supporting the assessment of malicious lateral movement.
The actor ran a VSSAdmin command to create shadow copies following RDP-session enumeration. Huntress assessed the activity as consistent with an attempt to obtain credentials from an Active Directory NTDS.dit copy.
After launching the SYSTEM-level shells, the actor enumerated active Remote Desktop Protocol sessions on the domain controller.
In the described incident, PsExec spawned SYSTEM-level command-shell processes on a domain controller, indicating privileged remote execution.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.