NPPSPY — Malware Profile

NPPSPY is an implementation of a theoretical mechanism first presented in 2004 for capturing credentials submitted to a Windows system via a rogue Network Provider API item. NPPSPY captures credentials following submission and writes them to a file on the victim system for follow-on exfiltration.

MITRE ATT&CK techniques (7)

Read the full analysis on IntelFusions