Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 2 actorsExploits 1 CVE

DWAgent

DWAgent is a legitimate remote administration tool that threat actors deploy post-compromise to maintain persistent remote access to victim systems and to facilitate follow-on activity. Across the provided reporting, DWAgent is repeatedly described as being installed after initial access as a persistence mechanism and remote control utility, often alongside other dual-use tools such as AnyDesk, Earthworm, and SharpHound. Observed use cases include enabling persistent access, remote control of compromised endpoints, deployment of additional payloads, and support for Active Directory reconnaissance.

The tool appears in multiple intrusion sets and campaigns. Sophos reported Akira ransomware operators using DWAgent in at least one case after gaining access, typically in broader operations involving credential theft, lateral movement, data exfiltration, and in some cases ransomware deployment. Rapid7 reported a 2026 intrusion assessed with moderate confidence as a MuddyWater/Seedworm false-flag operation under Chaos ransomware branding, where attackers established persistence through DWAgent and AnyDesk after Microsoft Teams-based social engineering and credential harvesting; the DWAgent installation chain included dwagent.exe, pythonw.exe, dwagsvc.exe, and dwaglnc.exe. Cisco Talos and related reporting described China-linked UAT-8837 using DWAgent after exploiting vulnerable servers or using compromised credentials, including exploitation of Sitecore CVE-2025-53690, to maintain access, conduct reconnaissance, and support additional malware deployment. In Sitecore exploitation reporting, DWAgent was installed as a SYSTEM service for persistence and used alongside Earthworm tunneling and SharpHound AD mapping.

Infection vectors in the provided content are indirect: DWAgent is not described as the initial malware used for intrusion, but rather as a post-exploitation tool dropped after successful compromise. Documented precursor access methods include unauthorized VPN access, Microsoft Teams social engineering with credential theft and MFA manipulation, exploitation of public-facing applications such as Sitecore CVE-2025-53690, and use of compromised credentials.

High-confidence indicators and artifacts directly mentioned in the content include the executable and component names dwagent.exe, pythonw.exe, dwagsvc.exe, and dwaglnc.exe; installation as a persistent service, including as SYSTEM in one Sitecore-related case; and Sophos detection WIN-PER-PRC-DWAGENT-INSTALL-1. Targeting context associated with DWAgent usage in the provided reporting includes small and medium-sized businesses across multiple sectors in Akira incidents, and critical infrastructure organizations in North America in UAT-8837 activity.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2025-53690Sitecore ViewState Deserialization RCE via Exposed Sample machineKeyExploited in the wild

On September 3, 2025, a critical zero-day vulnerability (CVE-2025-53690) in the Sitecore Experience Platform sent shockwaves through the enterprise content management community. Exploited in-the-wild, this flaw allowed remote attackers to gain full control of vulnerable sites through ViewState deserialization attacks... Attackers were able to exploit this weakness, crafting malicious payloads that allowed them to execute arbitrary code on impacted servers.

via cyberthronethecyberthrone.in
THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
MuddyWater

From there, the TA established persistence using remote access tools such as DWAgent and AnyDesk, before deploying additional payloads and further control of the environment.

via rapid7 blograpid7.com
UAT-8837

DWAgent, to enable persistent remote access and Active Directory reconnaissance

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1133External Remote ServicesEvidence1

The intrusion Rapid7 examined started through Microsoft Teams social engineering... and, in some cases, deployed AnyDesk for remote access.

T1190Exploit Public-Facing ApplicationEvidence1

Initial Access: The attacker targets Sitecore installations exposed to the internet, specifically those running with factory-default or sample machine keys.

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1

By submitting specially crafted POST requests (e.g., to /sitecore/blocked.aspx), attackers achieved remote code execution (RCE).

T1203Exploitation for Client ExecutionEvidence1

Exploited in-the-wild, this flaw allowed remote attackers to gain full control of vulnerable sites through ViewState deserialization attacks

Persistence

3 techniques
T1133External Remote ServicesEvidence1

The intrusion Rapid7 examined started through Microsoft Teams social engineering... and, in some cases, deployed AnyDesk for remote access.

T1543Create or Modify System ProcessEvidence1

The DWAgent installation chain included: dwagent.exe ... dwagsvc.exe DWAgent service

T1543.003Windows ServiceEvidence1

If the token is elevated, a service named CacheDB is created...

Privilege Escalation

2 techniques
T1543Create or Modify System ProcessEvidence1

The DWAgent installation chain included: dwagent.exe ... dwagsvc.exe DWAgent service

T1543.003Windows ServiceEvidence1

If the token is elevated, a service named CacheDB is created...

Discovery

1 technique
T1018Remote System DiscoveryEvidence1

Some of the notable tools include ... DWAgent, to enable persistent remote access and Active Directory reconnaissance SharpHound, to collect Active Directory information ... Certipy, a tool for Active Directory discovery and abuse

Lateral Movement

2 techniques
T1021Remote ServicesEvidence2

This included EARTHWORM for creating secret tunnels, DWAGENT for remote access, and SHARPHOUND for mapping the network.

T1021.001Remote Desktop ProtocolEvidence1

After establishing initial access, the threat actors utilized RDP sessions and DWAgent, another remote management tool, to maintain persistence.

Command and Control

2 techniques
T1105Ingress Tool TransferEvidence2

the threat actors downloaded and installed WinRAR... In one case, the actors installed both WinRAR and Google Chrome via explorer.exe

T1219Remote Access ToolsEvidence8

For command-and-control (C2), the threat actors frequently used the popular dual-use agent AnyDesk to establish persistent remote access... In one case, the actors also executed a DWAgent installer for remote access

Impact

1 technique
T1499.004Application or System ExploitationEvidence1

Sitecore, widely used by Fortune 500 companies and large organizations, was found to have a major flaw in its handling of ASP.NET ViewState when default or sample machine keys were present.

INDICATORS OF COMPROMISE

IOCs tracked for this family

6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
3 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
3 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
domain●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching6

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.