PsExec is a legitimate Microsoft Sysinternals remote administration utility for executing processes on local or remote Windows systems. Although not malware in itself, it is widely abused during intrusions and ransomware operations because it enables remote command execution over administrative shares and service creation, often using valid credentials already obtained by an attacker. In enterprise compromises, PsExec is commonly used for lateral movement, propagation of ransomware payloads, remote execution of batch scripts or binaries, and launching commands with elevated privileges, including SYSTEM context via its service-based execution model. It frequently appears alongside credential theft and post-exploitation tooling such as Mimikatz, Impacket, PowerShell Empire, Cobalt Strike, and WMI-based tradecraft.
PsExec has been repeatedly observed in ransomware and extortion operations including campaigns involving Conti, Black Basta, Akira, LockBit, Ryuk, Sodinokibi, DoppelPaymer, NetWalker, Maze, Petya or NotPetya, ProLock, Nefilim, Warlock, TFlower, and The Gentlemen. Threat actors use it after initial access obtained through vectors such as phishing, exploitation of public-facing applications, exposed remote services, stolen credentials, or supply-chain compromise. Once inside a network, operators commonly use harvested administrator or domain credentials to copy payloads to remote hosts and execute them through the temporary service PsExec creates, making it a reliable mechanism for rapid spread across Windows environments.
Because PsExec is an administrative tool rather than a malicious family, its presence must be interpreted in behavioral context. In malicious use cases it is strongly associated with lateral movement, privilege escalation to SYSTEM, post-exploitation activity, and ransomware deployment across reachable hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
38 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Additionally, they employ PsExec to remotely execute the ransomware binary on targeted systems, providing an alternative method for spreading the infection when the GPO-based approach is not feasible.
Microsoft also observed the use of PsExec and Impacket for lateral movement and the use of Group Policy Objects (GPO) to deploy the Warlock payload.
Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.
GOLD SALEM has been observed using PsExec and Impacket (WMI) for lateral movement within compromised environments.
"...publicly available utilities like PsExec, to move laterally within compromised networks."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
license validf scheduled task ... was created to execute ssh.exe on a recurring basis on the ServiceDesk system.
A new Group Policy Object (GPO) was created to launch and execute a Batch (BAT) file via a scheduled task.
PSExec remotely authenticated and executed PowerShell on remote systems within the environment.
ATT&CK Technique: Command and Scripting Interpreter: Windows Command Shell (T1059.003)
license validf scheduled task ... was created to execute ssh.exe on a recurring basis on the ServiceDesk system.
Lateral Movement: RDP hijacking, SMB/Admin shares, PsExec, VPN session abuse (T1021).
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote execution utility abused by the operator to obtain SYSTEM shells on local hosts during post-compromise operations.
Легитимный инструмент удалённого администрирования, используемый для lateral movement через SMB/Admin$ и запуска полезной нагрузки на удалённых системах; в тексте прямо указан как основной инструмент распространения ransomware у ряда групп.
PsExec is used for lateral movement and remote command execution, including obtaining a shell on the domain controller after pass-the-hash authentication.
PsExec is used by the operators as a lateral movement and remote execution utility to spread the ransomware across active domain systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.