Mimikatz — Malware Profile
Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks.
MITRE ATT&CK techniques (17)
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1003.004 LSA Secrets
- T1003.006 DCSync
- T1098 Account Manipulation
- T1134.005 SID-History Injection
- T1207 Rogue Domain Controller
- T1547.005 Security Support Provider
- T1550.002 Pass the Hash
- T1550.003 Pass the Ticket
- T1552.004 Private Keys
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1555.004 Windows Credential Manager
- T1558.001 Golden Ticket
- T1558.002 Silver Ticket
- T1649 Steal or Forge Authentication Certificates
IntelFusions coverage
- Andariel Acted as Play Ransomware Precursor in Five-Month Network Siege, Unit 42 Reveals 2026-02-16
- DOJ Charges Two APT27 Hackers as Unit 42 Confirms Group Still Active Across 45 Countries in 2025 2026-02-16
- U.S. and Allied Agencies Warn of North Korean Andariel Espionage Campaign Targeting Defense and Nuclear Sectors 2026-02-16
- Lazarus Group (APT38): North Korea's Most Prolific Cyber Threat Actor Targets Banks, Crypto, and Critical Infrastructure 2026-02-16
- APT39: Iran's Personal Data Harvesting Machine Targets Telecom and Travel Industries for Surveillance Operations 2026-02-16
- CISA, FBI, and NSA Joint Advisory: Conti Ransomware Surpasses 1,000 Attacks with TrickBot, Cobalt Strike, and Double Extortion 2026-02-16
- North Korean Andariel Group Linked to Play Ransomware in Unprecedented Nation-State Collaboration 2026-02-16
- DEV-0537 (LAPSUS$): Social Engineering, SIM Swapping, and Insider Recruitment Power a Pure Extortion and Destruction Campaign 2026-02-16
- Stately Taurus (Mustang Panda) Conducts Two-Year Southeast Asian Government Espionage Operation: Three-DLL ToneShell Variant, ShadowPad, and Continuous File Exfiltration via Dropbox 2026-02-16
- Kimsuky Adds Chrome Remote Desktop to Remote Control Arsenal Alongside AppleSeed, RDP Patcher, and Ngrok 2026-02-16
- OilRig's RDAT Backdoor Deploys Novel Steganographic Email C2 via Exchange Web Services: BMP-Hidden Commands Against Middle Eastern Telecom 2026-02-16
- Scattered Spider (UNC3944) 2025: Teleport as Novel C2 Persistence on AWS EC2, STONESTOP/POORTRY BYOVD EDR Termination, and DragonForce Ransomware Partnerships 2026-02-16
- Spectral Flux (NightSpire): Threat Actor Profile and Technical Analysis 2026-03-07
- NightSpire Kill Chain: How a FortiOS Zero-Day Became Ransomware's Favorite Front Door 2026-02-01
- Chinese hackers hit Southeast Asian energy grids with a new backdoor 2026-06-26
- Hackers disable Windows Defender and dump credentials after a ColdFusion break-in 2026-06-30
- Access broker exploits Citrix bug to plant DragonForce ransomware 2026-07-10
- New Go backdoor quietly steals government secrets across Southeast Asia 2026-07-17
- Hackers turn hacked SQL servers into mining rigs and VPN relays 2026-07-29
- Extortion crew claims data theft at Coca-Cola's Fairlife dairy arm 2026-07-29
- Russian factories hit by new ransomware built for Windows and ESXi 2026-07-30
Attributed threat actors
- Play Ransomware
- Dragonfly
- Sandworm Team
- OilRig
- Kimsuky
- APT29
- Earth Lusca
- TA505
- Blue Mockingbird
- DarkHydrus
- PittyTiger
- Turla
- Mustang Panda
- BRONZE BUTLER
- BlackByte
- APT27
- HEXANE
- FIN6
- Cleaver
- FIN7
- APT39
- APT32
- Akira
- GALLIUM
- FIN13
- APT41
- APT10
- Scattered Spider
- Whitefly
- APT5
- APT1
- LAPSUS$
- Carbanak
- APT35
- Tonto Team
- BackdoorDiplomacy
- Medusa Ransomware
- APT38
- Evil Corp
- Conti