Tool
PsExec
- First Reported
- Sep 8, 2025
- Latest Reported
- Sep 1, 2026
Reported Context (3)
- staging directories (e.g., C:\PerfLogs\, C:\Users\<username>\Documents\AVAST2\), lateral movement via PsExec, and domain-wide distribution through NETLOGON shares (e.g., \\<compromised Sophos Details GOLD SHERWOOD’s The Gentlemen Ransomware Playbook
- They used PsExec to remotely deploy Cobalt Strike DLL beacons to several remote hosts including a domain controller as well as file and backup servers. Lunar Spider Intrusion Used Tax-Themed JavaScript to Maintain Access for Nearly Two Months
- They then followed up by connecting to the domain controller over RDP with the built-in Administrator account and used PsExec to execute SystemBC with SYSTEM privileges on the host. DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
CVE (2)
Malware (10)
People (6)
Threat Actors (5)
MITRE ATT&CK (59)
Vendors (4)
Products (14)
Tools (23)
Countries (9)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.