HomeSecurityAbuse of PsExec to Execute Malicious Code

Abuse of PsExec to Execute Malicious Code

PsExec is one of the most controversial tools in the cybersecurity field. It is a legitimate system administration tool that is often used for malicious lateral movement campaigns .

PsExec

Recent threat reports show that PsExec remains among the top five tools used in cyberattacks through 2025, with groups ransomware such as Medusa, LockBit, and Kasseika actively leveraging it to spread across the network.

This ongoing abuse makes it imperative for security professionals to understand both the technical mechanisms of PsExec and the sophisticated ways in which malicious actors exploit its capabilities .

PsExec: How does it work?

PsExec operates through a sophisticated multi-step process that leverages core protocols and Windows. When legitimately executed, PsExec creates a temporary service on the target called PSEXESVC. This acts as a conduit for remote command execution. The tool begins by authenticating to the target system via the Server Message Block (SMB) protocol. It then connects to the ADMIN$ administrative share, which directly corresponds to the C:\Windows directory.

See also: Gemini CLI for Kali Linux: Penetration Testing Automation

The authentication process uses either the current login credentials or explicitly provided username and password combinations. After successful authentication, PsExec establishes a DCE/RPC (Distributed Computing Environment/Remote Procedure Call) connection to the target's Service Manager via the svcctl named pipe . This connection allows PsExec to create and manage services remotely , providing the basis for remote execution capabilities.

Abuse of PsExec to Execute Malicious Code

The service creation process involves uploading the PSEXESVC.exe binary to the ADMIN$ share and then registering it as a Windows service via the SCM interface. Once installed, the service creates named pipes for communication, typically psexecsvc for standard input/output, with additional pipes for stdin, stdout, and stderr. These pipes facilitate full bidirectional communication between local and remote systems, allowing for interactive command execution.

Malicious exploitation

Malicious actors are abusing the legitimate functionality of PsExec to achieve multiple malicious goals on compromised networks . CyberProof ’s “2025 Threat Report” lists PsExec as one of the top five tools used in attacks, highlighting its continued importance in modern threat campaigns.

See also: Deepfake Instagram: Ads use Gisele Bundchen

Attackers primarily exploit PsExec for lateral movement, after obtaining valid administrative credentials through various methods, such as credential dumping, password spraying, or exploiting stored credentials. The lateral movement process usually follows a predictable pattern. Attackers first compromise a primary system and harvest credentials with local administrative rights on the targets.

They then use PsExec to execute commands remotely, often deploying additional malware, creating backdoors, or establishing persistence mechanisms.

The tool's ability to execute commands with SYSTEM-level privileges makes it particularly attractive for disabling security checks and deploying ransomware payloads.

Recent ransomware campaigns show sophisticated patterns of PsExec abuse. The Medusa uses PsExec with the -c option to copy batch scripts to remote machines and execute them with SYSTEM privileges. These batch scripts often disable Windows Defender, create firewall rules to allow remote desktop connections, and modify registry settings to facilitate persistent access.

Similarly, collaborators LockBit have been observed using PsExec to remotely edit boot configuration data registry entries, specifically targeting VMware ESXi.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Hackers exploit AWS X-Ray service

Abuse of PsExec to Execute Malicious Code

Running PsExec produces numerous forensic artifacts that security teams can monitor to detect malicious activity. The most reliable indicator is the Windows event logs.

Mitigation Strategies

  • Effective prevention of PsExec abuse requires multi-layered security controls that cover both technical and procedural aspects. Network segmentation represents the fundamental defense, limiting opportunities for lateral movement even when attackers obtain valid credentials.
  • Organizations should implement strict firewall rules that control SMB traffic between network segments and monitor administrative share access.
  • “ Credential hygiene ” practices significantly reduce the chances of PsExec being abused. Implementing principles of least privilege , regular password rotations , and privileged access management (PAM) solutions limit the administrator credentials available to attackers.
  • Organizations should focus particularly on service accounts and shared administrative credentials that often provide broad network access.
  • Security teams should implement alerts for service installations with Event ID 7045, particularly those with unusual service names or executable paths.
  • Monitoring Named pipes via Event ID 5145 provides additional detection opportunities, especially when combined with SMB connection analysis.
  • Advanced defenses include adding application whitelisting, deploying endpoint detection and response (EDR), and behavioral analysis platforms. These technologies can detect PsExec abuse through pattern recognition and anomaly detection, even when attackers are using evasive techniques.
  • Regular threat hunting that focus on lateral movement indicators help organizations identify sophisticated attacks that bypass automated detection systems.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS