Impacket — Malware Profile
Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.
MITRE ATT&CK techniques (11)
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1003.003 NTDS
- T1003.004 LSA Secrets
- T1040 Network Sniffing
- T1047 Windows Management Instrumentation
- T1557.001 Name Resolution Poisoning and SMB Relay
- T1558.003 Kerberoasting
- T1558.005 Ccache Files
- T1569.002 Service Execution
- T1570 Lateral Tool Transfer
IntelFusions coverage
- Akira Ransomware Targets Cisco VPNs Without MFA: Sophos Documents Over a Dozen Incidents 2026-02-16
- APT41 Expands into Africa: Kaspersky Uncovers Wicked Panda's Sophisticated Campaign Against Government IT Services 2026-02-16
- Stately Taurus (Mustang Panda) Conducts Two-Year Southeast Asian Government Espionage Operation: Three-DLL ToneShell Variant, ShadowPad, and Continuous File Exfiltration via Dropbox 2026-02-16
- Access broker exploits Citrix bug to plant DragonForce ransomware 2026-07-10
- Hacked Korean websites pushed spy backdoors and Gunra ransomware 2026-07-30
- Spies hit Central Asian ministries with backdoors built per victim 2026-07-30
- FBI and CISA warn of Gunra ransomware hitting hospitals 2026-08-10
Attributed threat actors
- FIN13
- APT35
- APT41
- HAFNIUM
- Lotus Blossom
- APT27
- Mustang Panda
- Dragonfly
- Velvet Ant
- Storm-1811
- Cinnamon Tempest
- Volt Typhoon
- Storm-0501
- APT29
- APT10
- Andariel machine-inferred link
- MedusaLocker machine-inferred link
- BianLian machine-inferred link
- Medusa Ransomware machine-inferred link
- Chaos machine-inferred link
- Hive machine-inferred link
- Sandworm Team
- Ember Bear
- FIN8