wmiexec is an Impacket remote command-execution utility that uses Windows Management Instrumentation (WMI) to execute commands on Windows systems. It is a dual-use administration and penetration-testing tool rather than an inherently malicious malware family. It provides remote shell functionality and retrieves command output through an administrative SMB share, using timestamped output files that can help investigators reconstruct execution activity.
Attackers use wmiexec for post-compromise command execution, reconnaissance, and lateral movement. Observed activity includes remote execution of commands to identify the current user and movement between systems using an administrator account's NT password hash. Credential dumping performed by accompanying tools is distinct from wmiexec's remote-execution functionality.
Documented users include APT41, Volt Typhoon, FIN8, and the Memento ransomware operators. FIN8 used it during an intrusion at a U.S. financial institution, while Volt Typhoon employed it in operations affecting U.S. critical infrastructure. It has also been used for lateral movement in attacks against South Korean web-server environments. Its use is not specific to any single threat actor or campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In May, the attacker deployed the wmiexec remote shell tool and the secretsdump hash dumping tool to a Windows server.
The following is an example of the "dir" command being executed by wmiexec.py.
“A command line ending with ‘> \\127.0.0.1\ADMIN$\__<timestamp> 2>&1’ ... is an indicator of wmiexec usage.”
APT41 used the WMIEXEC utility to execute whoami commands on remote machines.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"Block process creations originating from PsExec and WMI commands ... to prevent lateral movement originating from PsExec and WMI, including Impacket’s WMIexec."
It was followed by the execution of discovery commands using wmiexec in the context of the built-in domain administrator account.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WMIExec is a tool for executing commands remotely on Windows systems via WMI, commonly used for lateral movement within networks.
Remote shell tool used by the Memento attackers to execute commands through Windows Management Instrumentation.
Remote execution/lateral movement utility leveraging WMI; here used to run discovery commands (whoami) on remote hosts.
An Impacket remote-execution utility used by FIN8 for lateral movement. Investigators identified its characteristic output-redirection syntax, including an ADMIN$ path containing a Unix-format timestamp.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.