PsExec is a legitimate Microsoft Sysinternals remote administration utility for executing processes on local or remote Windows systems. Although not malware in itself, it is widely abused during intrusions and ransomware operations because it enables remote command execution over administrative shares and service creation, often using valid credentials already obtained by an attacker. In enterprise compromises, PsExec is commonly used for lateral movement, propagation of ransomware payloads, remote execution of batch scripts or binaries, and launching commands with elevated privileges, including SYSTEM context via its service-based execution model. It frequently appears alongside credential theft and post-exploitation tooling such as Mimikatz, Impacket, PowerShell Empire, Cobalt Strike, and WMI-based tradecraft.
PsExec has been repeatedly observed in ransomware and extortion operations including campaigns involving Conti, Black Basta, Akira, LockBit, Ryuk, Sodinokibi, DoppelPaymer, NetWalker, Maze, Petya or NotPetya, ProLock, Nefilim, Warlock, TFlower, and The Gentlemen. Threat actors use it after initial access obtained through vectors such as phishing, exploitation of public-facing applications, exposed remote services, stolen credentials, or supply-chain compromise. Once inside a network, operators commonly use harvested administrator or domain credentials to copy payloads to remote hosts and execute them through the temporary service PsExec creates, making it a reliable mechanism for rapid spread across Windows environments.
Because PsExec is an administrative tool rather than a malicious family, its presence must be interpreted in behavioral context. In malicious use cases it is strongly associated with lateral movement, privilege escalation to SYSTEM, post-exploitation activity, and ransomware deployment across reachable hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
38 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Additionally, they employ PsExec to remotely execute the ransomware binary on targeted systems, providing an alternative method for spreading the infection when the GPO-based approach is not feasible.
Microsoft also observed the use of PsExec and Impacket for lateral movement and the use of Group Policy Objects (GPO) to deploy the Warlock payload.
Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.
GOLD SALEM has been observed using PsExec and Impacket (WMI) for lateral movement within compromised environments.
"...publicly available utilities like PsExec, to move laterally within compromised networks."
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers used batch files to execute multiple PsExec commands to deploy payloads to the identified machines.
Figure 4. Example of Microsoft Defender for Endpoint alerts for default service installation created by PsExec command... The following query finds default values for the ImagePath, DisplayName, and Description of the service installed on the remote system when using Sliver’s PsExec command.
If your user possesses these privileges, you can read and write ANY file on the system... stealing the locked Security Account Manager (SAM) and SYSTEM registry hives. Download these files... and use impacket-secretsdump or psexec to extract the local administrator NTLM hashes.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote execution utility abused by the operator to obtain SYSTEM shells on local hosts during post-compromise operations.
Легитимный инструмент удалённого администрирования, используемый для lateral movement через SMB/Admin$ и запуска полезной нагрузки на удалённых системах; в тексте прямо указан как основной инструмент распространения ransomware у ряда групп.
PsExec is used for lateral movement and remote command execution, including obtaining a shell on the domain controller after pass-the-hash authentication.
PsExec is used by the operators as a lateral movement and remote execution utility to spread the ransomware across active domain systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.