dcexe is an Active Directory credential-harvesting tool used during post-compromise operations. It performs DCSync by communicating with victim domain controllers over RPC and using the Directory Replication Service to retrieve sensitive directory information. Collected data includes account credentials, group memberships, trust relationships, domain identifiers, and replication metadata. The tool has been used by Chinese government-linked threat actors enabled by Integrity Technology Group, whose techniques overlap with activity tracked as Flax Typhoon, Ethereal Panda, and Red Juliett; these tracking labels are not necessarily equivalent. The broader operations target U.S. critical infrastructure and organizations across Southeast Asia, Africa, and North America. Its specific delivery mechanism is not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The actors also use DC.exe to perform DCSync, a technique that retrieves sensitive Active Directory data through directory replication.
The actors also use DC.exe to perform DCSync, a technique that retrieves sensitive Active Directory data through directory replication.
“The threat actors used DC.exe to execute the DCSync replication technique ... to copy sensitive information from the Active Directory.”
2 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named executable used to harvest credentials through DCSync. No specific exploited vulnerability or additional functionality is identified.
Tool used to retrieve Active Directory credentials, group memberships, and trust relationships through DCSync. It connects to domain controllers using RPC and requests directory data through the Directory Replication Service.
A credential-theft tool that abuses Active Directory replication through DCSync to obtain account credentials and directory information, including group memberships and trust relationships.
Offensive utility that uses RPC and the Directory Replication Service to replicate sensitive Active Directory information from a domain controller. It retrieves credentials, group memberships, trust relationships, and domain metadata through DCSync.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.