#PsExec
Storm-2570 Ransomware Tradecraft Across RaaS Operations socprime.com/active-threa...
Storm-2570 Ransomware Tradecraft Across RaaS Operations
Learn how Storm-2570 reuses RMM tools, Cloudflared, PsExec, and consistent TTPs across Qilin and DragonForce ransomware deployments
socprime.com
September 26, 2026 at 8:22 AM
🛠️ Tool Tuesday: PsExec

Sysinternals' remote-execution classic, and the ransomware operator's deployment tool of choice. In our cases, actors use PsExec to push the locker to dozens of hosts in seconds.

🔎 Hunt tip: w…

— from @TheDFIRReport (https://x.com/TheDFIRReport/status/2102359836012806148)
DFIR Report | Discover Public Cyber Threat Intelligence Report
t.co
September 22, 2026 at 12:45 PM
攻撃者がVSS、PsExec、secretsdumpを悪用してActive DirectoryのNTDS.dit認証情報を窃取

攻撃者がActive Directoryドメインコントローラーを標的にし、NTDS.dITデータベースに保存された認証情報を窃取するケースが増えています。 最近実施されたシミュレーションでは、脅威アクターがWindowsのネイティブ機能、リモート管理ツール、認証情報ダンプツールを組み合わせてActive Direct
攻撃者がVSS、PsExec、secretsdumpを悪用してActive DirectoryのNTDS.dit認証情報を窃取
攻撃者がActive Directoryドメインコントローラーを標的にし、NTDS.dITデータベースに保存された認証情報を窃取するケースが増えています。 最近実施されたシミュレーションでは、脅威アクターがWindowsのネイティブ機能、リモート管理ツール、認証情報ダンプツールを組み合わせてActive Direct
blackhatnews.tokyo
September 22, 2026 at 6:18 AM
@huntress.com
Attackers abuse VSS to delete recovery copies or extract NTDS.dit; correlate activity with lateral movement and credential harvesting.
-
IOCs: vssadmin, PsExec, NTDS[.]dit
-
#CredentialAccess #Ransomware #ThreatIntel
VSS Abuse Enables Ransomware and Credential Theft
www.huntress.com
September 14, 2026 at 8:02 PM
RMM-ber this ransomware. [Research Saturday]

Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing af…
#hackernews #news
RMM-ber this ransomware. [Research Saturday]
Ismael Valenzuela, Vice President of Labs, Threat Research and Intelligence at Arctic Wolf, sits down with Dave to discuss their work tracking Anubis. Arctic Wolf Labs details a series of 2026 Anubis ransomware intrusions, revealing affiliates using stolen VPN credentials and exploiting CitrixBleed 2 to gain initial access. Attackers then blended into legitimate IT activity by deploying RMM tools, using RDP and PsExec for lateral movement, stealing credentials, and establishing tunnels and proxies for persistence and exfiltration. The research highlights a repeatable attack chain defenders can disrupt before encryption, from suspicious remote access and unauthorized RMM deployment to credential theft, security-tool tampering, and ransomware execution. The research and executive brief can be found here: ⁠From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks
thecyberwire.com
September 6, 2026 at 1:44 PM
Hunting lateral movement: PsExec, WMI, RDP, Pass-the-Hash. Sysmon + Event 4624 type 3 para deteccion temprana.
https://malwareintel.es/blog/threat-hunting/hunting-lateral-movement/
#ThreatHunting #BlueTeam
August 20, 2026 at 7:00 AM
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration gbhackers.com/play-ransomw...
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe.
gbhackers.com
August 10, 2026 at 5:42 PM
Colombia's national CERT pulled apart an intrusion where the attackers quietly mined cryptocurrency on the victim's machines before encrypting them. The encryptor itself looks like parts of three different ransomware families bolted together.

#PsExec #ransomware #infosec
Ransomware crew mined crypto in Colombia before encrypting
Ransomware · IntelFusions threat intelligence
www.intelfusions.com
August 10, 2026 at 2:52 PM
Playランサムウェア、PsExecになりすまし正規のWindows管理業務に紛れ込む

Playランサムウェアは、侵入活動中の不審感を軽減するために、Windows管理ツールを装う手口を使っています。具体的には、PSexesvc.exeという名前のカスタムサービスバイナリを利用しています。アンチウイルス&マルウェア 同グループがMicrosoft SysinternalsのPsExecを模倣した...
Playランサムウェア、PsExecになりすまし正規のWindows管理業務に紛れ込む
Playランサムウェアは、侵入活動中の不審感を軽減するために、Windows管理ツールを装う手口を使っています。具体的には、PSexesvc.exeという名前のカスタムサービスバイナリを利用しています。アンチウイルス&マルウェア 同グループがMicrosoft SysinternalsのPsExecを模倣した
blackhatnews.tokyo
August 10, 2026 at 11:41 AM
ランサムウェアグループがCitrix Bleed 2、BYOD(Bring Your Own Device)、サプライチェーン認証情報を悪用

Anubisランサムウェア攻撃に関連する攻撃者が、Citrix Bleed 2(CVE-2025-5777)の脆弱性を悪用して初期アクセス権を取得していることが確認されています。

「関連組織によって戦術は異なるものの、正規のリモート管理・監視(RMM)ツール、認証情報へのアクセス、および横方向の移動に使用される直接的なキーボード操作手順の使用を通じて、共通のパターンが攻撃手法に現れた」と、アークティックウルフは今週発表した報告書で述べている。
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Arctic Wolf says Anubis affiliates abused RMM tools, VPN logins, RDP, PsExec, and cloud-transfer tools before ransomware deployment.
thehackernews.com
August 1, 2026 at 9:57 PM
NC Ransom Targets Healthcare and Education socprime.com/active-threa...
INC Ransom Targets Healthcare and Education
INC Ransom abuses Citrix flaws, AnyDesk, PsExec, and living-off-the-land tools to target healthcare, industrial, and education sectors
socprime.com
August 1, 2026 at 9:35 AM
Toy Ghouls deployed GenieLocker, a custom ransomware hitting Russian manufacturing firms since March 2026. Intrusions used stolen OpenVPN creds and tools like Mimikatz and PsExec, with no sign of data theft. #Russia #GenieLocker #ToyGhouls
Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a custom ransomware family used by Toy Ghouls against Russian organizations, especially in manufacturing, with Windows, Linux, and ESXi variants active since March 2026. The group used stolen OpenVPN credentials for entry, deployed tools like Mimikatz and PsExec, and encrypted systems without evidence of data theft or double extortion. #GenieLocker #ToyGhouls #Bearlyfy #Labubu #Laboo.boo #Mimikatz #PsExec #OpenVPN
www.hendryadrian.com
July 30, 2026 at 10:45 AM
Wie funktioniert PsExec unter Windows?

Unsere neue Anleitung zeigt Dir Schritt für Schritt, wie Du PsExec herunterlädst, vorbereitest und Befehle auf einem Remotecomputer ausführst.

www.windows-faq.de/2026/07/24/p...

#PsExec #Windows #Windows11 #Administration
PsExec unter Windows: Befehle remote sicher ausführen
PsExec unter Windows sicher nutzen: Download, Syntax, Befehle remote ausführen, SYSTEM Konto, wichtige Parameter, typische Fehler und Lösungen.
www.windows-faq.de
July 24, 2026 at 10:40 AM
Arctic Wolf found CVE-2026-0257 abused in June intrusions against Palo Alto firewalls to gain VPN access, then deploy Qilin ransomware with PsExec movement, credential theft, log clearing, and exfiltration. #CVE20260257 #PaloAlto #Qilin
Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware - Arctic Wolf
Arctic Wolf Labs found multiple June 2026 intrusions in which attackers used CVE-2026-0257 against Palo Alto Networks firewall appliances to gain VPN access and quickly deploy Qilin ransomware across victim networks. The activity showed shared operational patterns, including PsExec lateral movement, credential theft, log clearing, and in some cases data exfiltration for double-extortion, suggesting overlapping Qilin affiliates or shared exploitation infrastructure. #CVE-2026-0257 #PaloAltoNetworks #Qilin #GlobalProtect #PsExec
www.hendryadrian.com
July 21, 2026 at 2:15 PM
New Spirals Ransomware uses IIS Web Shell and PsExec to Encrypt IT Firm in under 24 Hours:

cybersecuritynews.com/new-spirals-...
July 20, 2026 at 5:55 AM
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours

potatosecuritynews.com/new-spirals-...

#Potatosecurity #ThreatIntel #Vulnerability
July 18, 2026 at 12:55 PM
Spirals ransomware rapidly encrypted a South Asian IT firm's network in under 24 hours, exploiting an IIS server and using PsExec for deployment. #PotatoSecurity #Ransomware #Spirals #ITSecurity thedailytechfeed.com/spirals-rans...
July 18, 2026 at 12:02 PM
Spirals ransomware rapidly encrypted a South Asian IT firm's network in under 24 hours, exploiting an IIS server and using PsExec for deployment. #CyberSecurity #Ransomware #Spirals #ITSecurity thedailytechfeed.com/spirals-rans...
July 18, 2026 at 12:02 PM
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours
A previously unseen ransomware family dubbed “Spirals” struck an IT services company in South Asia in June 2026. Symantec’s Threat Hunter Team reports that the attackers moved from the initial breach to full network encryption in under 24 hours. The Rust-based payload appears to be either entirely new or purpose-built for this single targeted attack, and the threat actor behind the operation remains unidentified. Spirals Ransomware Uses IIS Web Shell and PsExec The intrusion began on June 16 at 22:21 local time when the attackers compromised an internet-facing IIS web server and uploaded an ASP.NET web shell. Within minutes, they deployed three separate tunneling tools, including Chisel (disguised as chrome.exe ) and a Cloudflare tunnel client establishing redundant, covert communication channels. A token impersonation tool followed shortly after, which likely enabled privilege escalation. During a concentrated three-hour hands-on-keyboard session, the operator spawned cmd.exe and powershell.exe through the IIS worker process, performed a User Account Control (UAC) bypass, enabled Remote Desktop Protocol (RDP), created a persistent local account, and dumped the SAM hive. By 23:07, initial precursor activity showed active attempts to disable security tools. As detailed in the Spirals ransomware report , the attackers pivoted to WMI-based lateral movement at 23:33. They successfully hit over a dozen machines within minutes using compromised domain administrator credentials a rapid cadence strongly suggesting automated, pre-planned targeting rather than manual exploration. On June 17, the attackers shifted their tactics to using PsExec as their primary mass deployment vector. Starting around 14:12, a single compromised host pushed an identical base64-encoded PowerShell payload to network targets every few seconds for roughly 30 minutes. Managing compromised administrative tools inside a network mirrors the persistent perimeter struggles defenders face when managing SharePoint flaws exploited by opportunistic actors. This automated payload immediately disabled Windows Defender’s real-time monitoring and forcibly stopped over 20 critical backup, database, and virtualization services, including Veeam, VMware, SQL Server, and Exchange, effectively clearing open file handles ahead of encryption. The ransomware executable itself was named bitsadmin.exe to masquerade as a legitimate Windows utility. It was staged across multiple network locations, including the SYSVOL domain scripts directory, ensuring automated propagation even to machines not directly targeted by the PsExec script. This staging technique underscores why enterprise groups must audit internal script shares, much like they audit systems against archiving tool exploits that drop disguised binaries into legitimate directory trees. Spirals functions as a full-featured, Rust-based encryptor built with defense evasion, automated lateral movement, process termination, and privilege escalation capabilities. Cryptographic Component Implementation Specification Target Objective Symmetric Key Per-file AES-128 Secures the raw block data of targeted files Asymmetric Wrapper Attacker-controlled ECDH P-256 public key Protects the local AES keys from decryption Optimization Trick Intermittent encryption of jittered chunks Speeds up the locking cycle for files over 5 MB The ransomware leaves a local footprint to force negotiation: The ransom note is dropped across the system as C:\RECOVERY_SECTION.log . It threatens the public leak of stolen corporate data within six days if the target fails to pay. The note directs victims to a Tor negotiation portal, which Symantec confirmed explicitly names the threat family as “Spirals”. While Spirals has only been observed against a single victim so far, its operational discipline signals a highly skilled actor capable of rapidly scaling attacks. The combination of layered tunneling infrastructure, credential harvesting via LSASS dumps (using rundll32.exe and comsvcs.dll ), and domain-wide propagation via SYSVOL requires an immediate defensive response. Symantec’s indicator list includes dedicated staging infrastructure hosted at 185.141.216.194 alongside two compromised domains used for hosting malicious payloads. Organizations running internet-facing IIS servers should enforce the following priorities: Web Shell Detection: Actively monitor internet-facing web servers for unauthenticated ASP.NET file modifications or sudden process creations originating from IIS worker loops. Behavioral Auditing: Set immediate alerts on anomalous WMI and PsExec activity executing rapid, sequential connection attempts across internal zones. Credential Protection: Harden endpoints against LSASS memory dumping tools and tightly restrict domain administrator account usage on non-domain controllers.  Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. ->  Integrate ANY.RUN With Your SOC  Now . The post New Spirals Ransomware Uses IIS Web Shell and PsExec to Encrypt IT Firm in Under 24 Hours appeared first on Cyber Security News .
cybersecuritynews.com
July 18, 2026 at 11:59 AM
Detect lateral movement with Sysmon and PowerShell: Query Event ID 1 for processes spawned by svchost.exe or rundll32.exe with network connections, revealing PsExec or WMI-based attacks. Filter

https://www.valtersit.com/vault/sysmon-process-tree-analysis-for-lateral-movement-detection-b05460/
July 17, 2026 at 11:21 AM