Forfiles is not a standalone malware family but a legitimate Windows command-line utility (forfiles.exe) that has been exploited as a living-off-the-land binary (LOLBin) by multiple threat actors since at least 2018. First documented in TrickBot campaigns by CrowdStrike, Forfiles is used to execute malicious commands while bypassing application whitelisting and endpoint detection because it is a digitally signed Microsoft binary. It falls under the category of LOLBin abuse (MITRE ATT&CK T1218.011).
Adversaries use Forfiles with the /c parameter to launch arbitrary commands, such as PowerShell one-liners, to download secondary payloads, execute ransomware binaries, or perform reconnaissance. The typical attack vector involves a malicious document or script that invokes forfiles.exe in a command line like forfiles.exe /p C:UsersPublic /m *.pdf /c "cmd /c powershell -EncodedCommand ...". Propagation occurs through spear-phishing emails with malicious attachments or links, and lateral movement via SMB or RDP after initial access. The binary can be executed from any directory, and persistence is achieved by scheduling Forfiles-based tasks in Windows Task Scheduler or adding registry Run keys. Evasion relies on the trusted signature of Microsoft binaries, making it difficult for legacy signature-based antivirus to detect. The technique is frequently used by TrickBot, Emotet, Qakbot, and IcedID (MITRE ATT&CK T1059.001, T1204.002).
Forfiles abuse first appeared in TrickBot campaigns around 2018, as reported by Trend Micro and CrowdStrike. In 2020, Emotet operators used Forfiles to execute PowerShell commands that deployed Cobalt Strike beacons, leading to ransomware attacks by Ryuk and Conti. Notable incidents include the 2020 attack on Universal Health Services (UHS) where Ryuk was deployed via TrickBot leveraging Forfiles. No specific CVE is associated with Forfiles itself, as it is a built-in utility.
Behavioral signatures include command-line arguments matching the pattern forfiles.exe /p [path] /m [mask] /c [command], especially when the /c parameter contains encoded PowerShell or base64 strings. Network indicators include outbound connections to C2 infrastructure (e.g., IP ranges associated with TrickBot or Emotet) shortly after forfiles.exe execution. No unique file hashes exist as forfiles.exe is a standard Windows file; however, parent-child process anomalies (e.g., forfiles.exe spawning cmd.exe or powershell.exe) are strong indicators. Registry keys such as HKCUSoftwareMicrosoftWindowsCurrentVersionRun may contain forfiles.exe commands. MITRE detection rules (e.g., from the ATT&CK Navigator) recommend monitoring process creation events with event ID 4688.
The primary risk is the deployment of ransomware (e.g., Ryuk, Conti) or information stealers (e.g., IcedID) leading to data exfiltration and operational shutdowns. Financial losses in the tens of millions have been reported for healthcare and manufacturing sectors. The use of a trusted binary complicates forensic attribution and extends dwell time.
Mitigation includes restricting execution of forfiles.exe to authorized administrators via AppLocker or Windows Defender Application Control, enabling attack surface reduction rules (e.g., blocking processes spawned from wscript.exe or forfiles.exe), and monitoring for anomalous forfiles.exe command lines using SIEM rules based on MITRE ATT&CK T1218.011. No patch is available since the utility is legitimate; instead, organizations should adopt application whitelisting and user training against phishing.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.