Microsoft starts removing WMIC tool used by cybercriminals

A crucial tool for cybercriminals is being phased out by Microsoft, marking a significant step towards improving the security of Windows devices. The company has started removing the Windows Management Instrumentation Command-line (WMIC) tool from various versions of its operating system, including Windows 11 24H2 and 25H2.

For those unfamiliar with WMIC, it’s a legacy built-in Windows command-line utility that helps interact with the Windows Management Instrumentation (WMI) system using text commands. Despite being deprecated in 2016 for Windows Server 2012 and again in 2021 for Windows 10 21H1, WMIC has continued to be used by cybercriminals to launch malicious attacks.

This tool has been identified as a LOLBIN, or living-off-the-land binary, which means it’s a legitimate Microsoft-signed executable that threat actors have exploited to carry out various malicious activities. For instance, ransomware encryptors often use the WMIC command to delete Shadow Volume Copies, making it difficult for victims to recover their encrypted data.

Other malicious uses of WMIC include querying for installed security solutions and antivirus software, uninstalling them, and even adding exclusions to Microsoft Defender to evade detection on compromised systems. This tool has been a popular choice among attackers due to its ability to execute various tasks without raising suspicions, as it’s a legitimate Windows utility.

The removal of WMIC is expected to improve the overall security posture of Windows devices by disrupting the tactics used by cybercriminals. By disabling this tool, Microsoft aims to prevent malware from carrying out certain malicious activities that rely on WMIC’s functionality.

For IT administrators who have been using WMIC for system management tasks, Microsoft recommends switching to more modern tools such as PowerShell or WMI’s COM API. The company has provided guidance and recommendations in a support document to help with the transition.

The removal of WMIC is a welcome move towards improving Windows security, but it’s essential for users to be aware of the potential risks associated with this tool. To stay secure, it’s crucial to keep software up-to-date, use reputable antivirus solutions, and implement robust cybersecurity measures to prevent attacks.

In conclusion, the removal of WMIC marks an important step in Microsoft’s efforts to improve Windows security. As cybercriminals continually evolve their tactics, it’s essential for users to stay informed about potential vulnerabilities and take proactive measures to protect themselves against emerging threats.


Source: Bleeping Computer — 2026-08-18