/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Ransomware attack leveraged Windows' remote admin access tools like Windows Management Instrumentation (WMI) and PsExec to infect other PCs on network

Russell Brandom / The Verge :

The Verge Russell Brandom

Context & Ripple Effects

This attack lands just weeks after WannaCry swept unpatched Windows machines via EternalBlue, but it marks a different technique: instead of exploiting a vulnerability to break in, the ransomware uses legitimate Windows administration utilities — WMI and PsExec — that are already present on corporate networks to hop from PC to PC once inside.

That pattern has only hardened since. Microsoft later catalogued how crews behind REvil, Samas, Doppelpaymer, Bitpaymer, and Ryuk run manually controlled, human-operated campaigns rather than automated worms, and attackers have kept turning trusted remote-access software into entry points — from MOVEit hackers exploiting a zero-day in IT support tool SysAid to a flaw in ConnectWise's remote access tool that researchers called embarrassingly easy to exploit.

First-order effects

  • Organizations hit by this campaign face reinfection of every machine their admin credentials can reach, because WMI and PsExec give the malware the same network-wide reach IT staff rely on.
  • Windows administrators must immediately treat their own management tooling as a potential infection vector, auditing which accounts can invoke WMI and PsExec across the network.

Second-order effects

  • Security vendors are pushed to build detection around anomalous use of legitimate admin tools rather than malware signatures alone, since the spreading mechanism is native Windows functionality.
  • Enterprises begin restricting or segmenting remote administration capabilities — the same instinct that later drove scrutiny of third-party remote-access tools like SysAid and ConnectWise when they became attacker doorways.

Third-order effects

  • If the pattern holds, ransomware consolidates around the human-operated model Microsoft described for REvil and Ryuk: small numbers of skilled operators living off built-in enterprise tooling, which erodes the line between malicious code and trusted software and shifts defense toward identity and privilege control rather than perimeter blocking.

The trend: Ransomware is evolving from self-spreading exploits like EternalBlue toward operators who weaponize the legitimate administrative and remote-access tools already inside enterprise networks.