Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 1 actor

Impacket WMIEXEC

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC3524

"UNC3524 used a customized version of Impacket’s WMIEXEC."

via mandiant threat intelligencecloud.google.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

2 techniques
T1047Windows Management InstrumentationEvidence2
TacticExecution

in some cases utilized the Impacket module wmiexec to move laterally.

T1059.003Windows Command ShellEvidence1
TacticExecution

"...writing command outputs to a file..." and "...using the built-in reg save command..." and "MITRE ATT&CK... Execution... T1059.003: Windows Command Shell"

Stealth

1 technique
T1027Obfuscated Files or InformationEvidence1
TacticStealth

"Mandiant has observed UNC3524 modifying the hardcoded file path (\\127.0.0.1\ADMIN$\debug\DEBUG.LOG ) to evade basic detections..."

Lateral Movement

2 techniques
T1021.003Distributed Component Object ModelEvidence1

"UNC3524 used a customized version of Impacket’s WMIEXEC... WMIEXEC uses Windows Management Instrumentation to establish a semi-interactive shell on a remote host."

T1550.002Pass the HashEvidence1

Lateral Movement - Pass the Hash (T1550.002). Полученный NT-хеш работает для аутентификации на других серверах без знания пароля. CrackMapExec, impacket-psexec , impacket-wmiexec - выбор зависит от целевой машины.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.