PsExec — Malware Profile
PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.
MITRE ATT&CK techniques (5)
- T1021.002 SMB/Windows Admin Shares
- T1136.002 Domain Account
- T1543.003 Windows Service
- T1569.002 Service Execution
- T1570 Lateral Tool Transfer
IntelFusions coverage
- Andariel Acted as Play Ransomware Precursor in Five-Month Network Siege, Unit 42 Reveals 2026-02-16
- Akira Ransomware Targets Cisco VPNs Without MFA: Sophos Documents Over a Dozen Incidents 2026-02-16
- APT39: Iran's Personal Data Harvesting Machine Targets Telecom and Travel Industries for Surveillance Operations 2026-02-16
- North Korean Andariel Group Linked to Play Ransomware in Unprecedented Nation-State Collaboration 2026-02-16
- Scattered Spider (UNC3944) 2025: Teleport as Novel C2 Persistence on AWS EC2, STONESTOP/POORTRY BYOVD EDR Termination, and DragonForce Ransomware Partnerships 2026-02-16
- MosesStaff Technical Analysis: PyDCrypt Loader and DCSrv Wiper Use DiskCryptor for Ideologically Motivated Destruction Without Ransom 2026-02-16
- Dragonfly 2.0: Sophisticated Energy Sector Threat Group Returns with Sabotage-Ready Access to Operational Systems 2026-02-16
- Spectral Flux (NightSpire): Threat Actor Profile and Technical Analysis 2026-03-07
- NightSpire Kill Chain: How a FortiOS Zero-Day Became Ransomware's Favorite Front Door 2026-02-01
- Gentlemen ransomware gang builds custom backdoor and stealthy network spying 2026-06-29
- Companies miss most intrusions, some for years, Kaspersky finds 2026-07-02
- Hacked Korean websites pushed spy backdoors and Gunra ransomware 2026-07-30
- Russian factories hit by new ransomware built for Windows and ESXi 2026-07-30
- Ransomware hits Brazil's schools using stolen logins 2026-08-03
- Ransomware crew mined crypto in Colombia before encrypting 2026-08-10
- FBI and CISA warn of Gunra ransomware hitting hospitals 2026-08-10
Attributed threat actors
- Moses Staff
- Play Ransomware
- AvosLocker machine-inferred link
- DarkSide machine-inferred link
- Dragonfly
- Royal machine-inferred link
- Sandworm Team
- OilRig
- Kimsuky
- PYSA machine-inferred link
- APT29
- INC Ransom
- Turla
- BlackSuit machine-inferred link
- BlackByte
- Anubis machine-inferred link
- SafePay machine-inferred link
- HAFNIUM
- 3AM machine-inferred link
- FIN6
- Cleaver
- Lynx Ransomware machine-inferred link
- Fox Kitten
- Water Galura machine-inferred link
- Qilin machine-inferred link
- FIN8
- APT39
- Akira
- GALLIUM
- The Gentlemen machine-inferred link
- APT10
- Naikon
- Storm-1811
- ALPHV/BlackCat machine-inferred link
- Snatch machine-inferred link
- Vice Society machine-inferred link
- NightSpire machine-inferred link
- DarkVishnya
- APT1
- MedusaLocker machine-inferred link