The Risk of LOLBins: How Attackers Abuse Trusted System Binaries

Key Takeaways:

  • LOLBins are legitimate, often built-in system tools that threat actors repurpose to carry out attacks, frequently without installing any new software.
  • Because these binaries are trusted by design, they often evade traditional antivirus and other tools that focus mainly on malicious files.
  • Attackers use them to move through a network, escalate privileges, and steal data while looking like normal admin activity.
  • Common examples include PowerShell, PsExec, certutil, mshta, and rundll32—tools your organization is likely already running right now.

The Risk of LOLBins: How Attackers Abuse Trusted System Binaries

Key Takeaways:

  • LOLBins are legitimate, often built-in system tools that threat actors repurpose to carry out attacks, frequently without installing any new software.
  • Because these binaries are trusted by design, they often evade traditional antivirus and other tools that focus mainly on malicious files.
  • Attackers use them to move through a network, escalate privileges, and steal data while looking like normal admin activity.
  • Common examples include PowerShell, PsExec, certutil, mshta, and rundll32—tools your organization is likely already running right now.

What are LOLBins?

LOLBins, short for "living-off-the-land binaries," are legitimate, often pre-installed system tools that threat actors abuse to carry out an attack instead of relying on custom malware. Think PowerShell, Windows Management Instrumentation (WMI), or command-line utilities that ship with every version of Windows. For a full breakdown of what LOLBins are and how they work, see our guide on LOLBin protection tools.

The short version: they're not malicious on their own. They only become a threat when someone with bad intentions puts them to bad use.


Why trusted binaries are dangerous

The thing that makes LOLBins useful to your IT team is the exact same thing that makes them dangerous in a threat actor's hands: trust.

They already have permission to run. Many traditional security tools are built to flag things that don't belong—unfamiliar files, unsigned executables, code that doesn't match a known signature. LOLBins often don't trip those alarms because they're signed, native, and expected. A tool built to catch strangers has less reason to stop someone who already has a key.

They blend into normal activity. An user running PowerShell doesn't look like an attack. It looks like Tuesday. Threat actors count on this. They use trusted binaries specifically because the activity hides inside the noise of everyday admin work, making it easy to miss unless someone is looking closely at the context—who ran it, from where, and why.

They give attackers a full toolkit without the risk. Once inside a network, threat actors can use LOLBins to move laterally, escalate privileges, disable security controls, and exfiltrate data—often without writing new files to disk. Fewer new files mean fewer signatures to match, so traditional antivirus may have little or nothing obvious to flag.

They lower the cost of an attack. Building custom malware takes time, money, and skill. Repurposing tools that are already sitting on most endpoints is faster, cheaper, and far less likely to get caught early. That's a big part of why LOLBin abuse shows up in everything from ransomware operations to nation-state espionage.

They complicate response and forensics. When an attack is built entirely out of native, trusted tools, it's harder to tell where legitimate IT work ends and an intrusion begins. Investigators have to dig into behavior and context instead of just flagging a bad file, which takes more time and more expertise.


Common LOLBin examples

Threat actors gravitate toward a fairly consistent set of tools because they're widely available on Windows systems and flexible enough to support each stage of an intrusion.

  • PowerShell — used for everything from downloading payloads to running scripts entirely in memory
  • PsExec — lets attackers execute commands on remote systems, often to move laterally across a network
  • certutil — a certificate tool that can be repurposed to decode or download malicious files
  • mshta — runs Microsoft HTML Applications, often used to execute malicious scripts while looking like routine activity
  • rundll32 — executes code from DLL files, a common way to run malicious code without dropping a new executable
  • wmic — used for system reconnaissance and to run commands across a network
  • regsvr32 — can be used to run scripts remotely while evading tools that only look for suspicious file types
  • bitsadmin — designed for file transfers, but frequently abused to download and install malware quietly

None of these tools are inherently malicious. Every one of them has a legitimate job to do. That's exactly the point, and exactly the risk.


What this means for your security strategy

If your security strategy is built around catching bad files, attackers can use LOLBins to find the gaps. Stopping this kind of attack means shifting the focus from what's running to how it's running and who's behind it. That's the difference between a security tool that misses the activity entirely and one that catches it before it turns into a real incident.

Want to know what to look for in a tool built to catch this kind of behavior? Check out our guide on LOLBin protection tools to see what actually works—and how Huntress helps.


Protect What Matters

Secure endpoints, email, and employees with the power of our 24/7 SOC. Try Huntress for free and deploy in minutes to start fighting threats.
Try Huntress for Free