PsExec
MITRE ATT&CK: S0029 View on attack.mitre.org
Aliases: PsExec
- Operating systems
- windows
- Related IoCs
- 14 (4 malicious)
- Last IoC activity
- 2026-09-03 03:38:53
- Profile updated
- 2026-07-07 15:32:29
Context
PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to PsExec (S0029). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | dcky6u1m8u6el.cloudfront.net | 2026-09-03 | 2 |
| file sample | ocspackage.exe | 2026-01-05 | 1 |
| file sample | PsExec.exe | 2025-08-02 | 1 |
| file sample | PsExec64.exe | 2025-02-15 | 1 |
Detection coverage
- 120 Sigma rules
Malware & tools used
- SMB/Windows Admin Shares (attack-pattern)
- Windows Service (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Service Execution (attack-pattern)
- Domain Account (attack-pattern)
Used by threat actors
- SharePoint ToolShell Exploitation (campaign)
- 2025 Poland Wiper Attacks (campaign)
- CostaRicto (campaign)
- Night Dragon (campaign)
- Operation Wocao (campaign)
- Operation Ghost (campaign)
- Quantum Ransomware Compromise (campaign)
- Sandworm Team (threat-actor)
- Magic Hound (threat-actor)
- Medusa Group (threat-actor)
- Fox Kitten (threat-actor)
- Volt Typhoon (threat-actor)
- Indrik Spider (threat-actor)
- INC Ransom (threat-actor)
- FIN8 (threat-actor)
- Naikon (threat-actor)
- FIN5 (threat-actor)
- Dragonfly (threat-actor)
- FIN6 (threat-actor)
- APT39 (threat-actor)
- GALLIUM (threat-actor)
- menuPass (threat-actor)
- Kimsuky (threat-actor)
- OilRig (threat-actor)
- Thrip (threat-actor)
Reports & references
- MITRE ATT&CK — S0029 (report)
- Microsoft — Bb897553 (report)
- sans.org — Protecting Privileged Domain Accounts Psexec Deep Dive (report)