• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    DragonForce/CRPx0 Lateral Movement via WMI and Remote Schtasks

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 21 days ago•0•0•1

    Detects lateral movement activities involving the use of WMIC to remotely create processes or Schtasks to remotely create scheduled tasks. These techniques are often used by threat actors, including those associated with DragonForce and CRPx0 ransomware, to propagate across a network by executing commands on remote systems.

    Sigma

    Tags

    T1047 - Windows Management InstrumentationT1053.005 - Scheduled TaskT1021 - Remote ServicesTA0002 - ExecutionTA0003 - PersistenceProcess CreationWmi ActivityScheduled Task CreatedCommand ExecutionWindowsWindows Wmi ServiceWindows Task Scheduler Serviceattack.t1047attack.t1053.005attack.t1021

    Found in

    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026
    • Analysis of DragonForce Windows Ransomware LockerLast updated Sep 9, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?