Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 12, 2026
- Feed role
- C2 / Distribution
- Host form
- 13 IP / 9 hostnames
Mimikatz is a Windows post-exploitation credential-access tool widely used by penetration testers and threat actors.
Profile source: Mallory opens in a new tabMimikatz
Mimikatz is a Windows post-exploitation credential-access tool widely used by penetration testers and threat actors. It extracts plaintext credentials, NTLM password hashes, Kerberos tickets, LSA secrets, Security Account Manager data, and other credential material from Windows memory and protected credential stores. Its capabilities support credential dumping from LSASS, extraction of domain and local account secrets, and credential-abuse techniques including Pass-the-Hash, Overpass-the-Hash, and DCSync, enabling lateral movement and domain compromise. Mimikatz has been observed in intrusions involving BISMUTH, Cuba ransomware affiliates, Toy Ghouls, The Gentlemen affiliates, LockBit affiliates, Warlock, Storm-1175, and other financially motivated and espionage-oriented operators. It is generally introduced after an attacker has already obtained access to a Windows environment rather than serving as an initial-access payload.
C2 tracking
Derp observations, rolling seven-day window
Samples
1aa1a8812eb84a59de7fd4a6911742b6337d59b450c65639a30fdbf8ea106c1d 2cb34d4ad1394faf548074d935bbd147df9821ac174b48a65466cacb3ff714ba 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 31dcd05530762305d17c3ca6faa00678aebfd59c726a73e82dc7da2187bb66b2 32f128e831af8c8539b0eda7d02a0b0e3935fd5d65c091ee052c2f85be6bcb0d 53422051d1863ad44309833893d1f6acc6c0e0509e4871d9083f190feadaf068 7a1e3aa4aa206dde371bac061f0ee6f11e3cacf0e49348d46f3cb8cda4935f64 994d9ec72bff0b085f5eda14b8e42391400717dfb843229c167171c555b0d625 05dbb515120ec8a6a453c91833eacf432e67ffe89fd650ac704eefc6bf8de290 32ead15908ca61088701ec6ee4c692658585746bafb52cce23c047d035fc91a5 Reported operators
"The group used DebugView and the malicious DLL ... to launch Base64-encoded Mimikatz commands" including "sekurlsa::logonpasswords" and "lsadump::lsa /inject."
The threat actor created an Administrator account and attempted to dump credentials using Mimikatz, but this was prevented by Elastic Defend.
"Mimikatz is an offensive security tool used to collect and inject passwords from compromised systems"; the SEKURLSA::LogonPasswords module was observed.
A separate LSASS memory dump and Mimikatz supplied additional routes to credentials.
Toy Ghouls uses mimikatz to access LSA secrets, extract LSASS data and credentials, and perform Pass-the-Hash, Overpass-the-Hash, and DCSync techniques.
Récupération du PID de LSASS : tasklist /v /fo csv | findstr /i "lsass". Usage de Mimikatz confirmé par des recherches tierces.
C:\Users\Public\mimi.exe is listed as a Mimikatz path explicitly checked by the affiliate's credential-harvesting script.
The following TTPs and IOCs have been published by multiple researchers ... TA0006 - Credential Access Mimikatz.
The group is using AnyDesk or SimpleHelp, Advanced IP Scanner for reconnaissance, and Mimikatz to dump credentials from the LSASS process.
Previous research indicates that the threat actors employed Mimikatz and registry hive dumping.
User credentials are gained through a variety of different means including exploitation of public-facing appliances, insecurely stored credentials, extracting the Active Directory database file (NTDS.dit), enumerating existing stored sessions, credential dumping through LSASS, and use of the Mimikatz and Impacket tools
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT.
Mimikatz – an open source tool designed to extract and use credential information from Windows systems
Chafer has also continued to use tools previously associated with the group, including its own custom backdoor Remexi; the aforementioned PsExec; Mimikatz (Hacktool.Mimikatz), a free tool capable of changing privileges, exporting security certificates, and recovering Windows passwords in plaintext.
The system stealer attempts to obtain credentials from LSASS with a technique similar to that used by Mimikatz.
In order to stealth authentication materials on compromised hosts, adversaries relied on the mimikatz tool.
This was performed using several open-source utilities, including nanodump and mimikatz.
However, in singular cases we have seen the group downloading and using the Mimikatz password-dumping tool as well... During the attack, we suspect the group also employing Mimikatz for credentials harvesting.
Using DUSTTUNNEL's command-and-control functions, CHERNOVITE could drop additional tools such as Mimikatz to gather credentials to access a legitimate account and gain a persistent foothold in the enterprise network.
The group also installs Mimikatz and RDP Wrapper, which have both been steadily used for many years.
The group used DCSync attacks and Mimikatz to perform privilege escalation routines.
The Variations in the playbook ... Credential harvesting using tools such as Mimikatz and Procdump.
MuddyWaters uses different types of attacks for initial access like phishing email campaigns, using tools like MimiKatz to break into the system, etc.
Following tools were found in the lateral movement stage â—‹ Mimikatz â—‹ secretdump.py â—‹ PsExec â—‹ csvde â—‹ WinRAR
Kerberos golden ticket tool based on the Mimikatz credentials stealer
The threat actor used Mimikatz to dump the credentials on the server they gained their initial access on.
The attackers used CobaltStrike, which was downloaded to the victim’s computer using the certutil.exe utility, compiled aspx webshells, the procdump tool, and Mimikatz.
32- and 64-bit signed builds of this password dumper were also found among several victims compromised by Winnti variants installed from the Install.exe dropper, sometimes in conjunction with Mimikatz.
Additional activity related to credential theft was observed approximately one week after the use of GetUserSPNs.ps1, with the observation of Mimikatz on a user's workstation being written into the user’s document folder as a zipped file.
Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • Mimikatz est un outil qui peut notamment servir à extraire les mots de passe (ou leurs empreintes) stockés en mémoire sous Windows;
Playful Taurus used Mimikatz to dump credentials and generate Kerberos Golden Tickets.
Symantec has the following protection in place to protect customers against Elfin attacks: ... Hacktool.Mimikatz ... Symantec has the following protection in place to protect customers against Chafer attacks: ... Hacktool.Mimikatz ...
This includes the credential-theft tool Mimikatz and UPX-packed artifacts related to the Equation Group set of exploits.
Shortly after this, the well-known credential-stealing tool Mimikatz was executed from %USERPROFILE%\documents\x64.
these modules, loaded by operators at completely random or sporadic moments during malware execution, are part of the Mimikatz tool. In other words, in order to evade behavioral signatures and avoid detection, attackers have “chopped up” the aforementioned tool using only the logic of the DCSYNC attack.
Among the open-source tools frequently utilized are SoftEther VPN for secure communications, Mimikatz for credential harvesting, and VNT for network traversal.
With the defenses lowered, the attackers installed tools including NirSoft and Mimikatz, which are used to steal credentials, cookies, live network traffic and more, with the aim of finding means to gain further control over the machine and the wider network, including administrator accounts.
Asking for an alternative application to mimikatz.
Additionally, Mimikatz, the Fscan scanner, the gost proxy, and the user account creation tool can be used as plugins.
Mimikatz — dump de credentials en mémoire
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001).
FIN7 and Carbanak abused ProcDump to dump LSASS memory â–¸ PowerShell Mimikatz scripts also widely used
FIN7 and Carbanak abused ProcDump to dump LSASS memory â–¸ PowerShell Mimikatz scripts also widely used
Along with the classical abuse of Microsoft SysInternal tools such as PsExec and other well-known open-source tools such as Putty and the never-missing Mimikatz, during recent operations, Makop abused even more peculiar software.
A customized modification of the original Mimikatz, Mimikat.dll was designed to specifically inject the Skeleton Key to allow the attackers persistent, unfettered Lateral Movement across the network.
Additional tradecraft and techniques: Using open-source tooling: Mimikatz, Hekatomb, Lazagne, gosecretsdump, smbpasswd.py, LinPEAS, ADFSDump.
The adversary used mimikatz to obtain user credentials. They saved the utility file under the name calculator.exe to disguise its real purpose.
For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.
Microsoft’s profile of the group noted the execution of Mimikatz “specifically targeting the Local Security Authority Subsystem Service (LSASS) memory to extract plaintext credentials.”
The investigation identified tools for obtaining credentials. Besides the publicly available mimikatz utility, the attackers used secretsdump and ProcDump.
We detected the use of the Mimikatz utility in some of the investigated attacks.
Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
Before that, however, antivirus on HSE endpoints detected both Cobalt Strike and Mimikatz being deployed on the so-called Patient Zero workstation.
To laterally move within the target network, Mimikatz was used to dump passwords.
Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."
To facilitate privilege escalation, SHADOW-EARTH-053 has been found to use Mimikatz, while lateral movement is accomplished using a custom remote desktop protocol (RDP) launcher and C# implementation of SMBExec known as Sharp-SMBExec.
"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."
"It also uses two custom versions of Mimikatz..."
“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”
"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."
"...other tools including Mimikatz..."
"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."
"...using the credential harvesting tool Mimikatz."
"...using the credential harvesting tool Mimikatz."
Persistence is achieved by emplacement of ASPX webshells that allow execution of Mimikatz for credential recovery.
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
The GreyEnergy group uses fairly standard tools for these tasks: Nmap and Mimikatz.
"Pypykatz (a Python version of Mimikatz)"
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
“The group continues to push various custom Mimikatz variants and keyloggers for credential harvesting purposes…”
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.
...a manual on deploying Cobalt Strike, mimikatz to dump NTLM hashes...
Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
Sandworm Team used UPX to pack a copy of Mimikatz.
Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.
We identified a different config.dat file being used for different purposes, like information gathering through Pyxie, Lazagne and Mimikatz...
...an operator repeatedly and infrequently revisited a compromised network whenever an Endpoint Detection and Response (EDR) tool detected or quarantined tools like HYPERBRO and Mimikatz.
"A modified mimikatz which extracts passwords from memory."
"...immediately executed a Zerologon exploit against the organization’s domain controller using the Mimikatz tool."
The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.
The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.
Attackers also used Getpass, a custom Mimikatz DLL, masquerading as a Palo Alto tool, which automatically harvests credentials from 10 Windows authentication packages by accessing lsass.exe memory.
Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.
"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."
Microsoft Defender Antivirus detects threat components as ... HackTool:Win32/Mimikatz ... HackTool:Win64/Mimikatz
"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."
Exploited software
MITRE ATT&CK
Reporting
Check Point Research reported that Microsoft’s Windows Defender Boot-Time Removal driver, BTR.sys, can be repurposed as a Microsoft-signed kernel-mode primitive for arbitrary file and registry operations. After reverse engineering the driver, the researcher documented its RC4-encrypted transaction format and integrity checks, then built a proof-of-concept tool, BTR_CLI, that generates valid transactions, stages the driver, and executes actions on systems ranging from Windows 7 through Windows 11. The report says the driver’s legitimate remediation capability could let an attacker abuse a boot-time “golden window” to bypass or weaken EDR and antivirus protections before higher-level defenses fully initialize, including deleting Defender binaries and modifying protected registry keys. Check Point said it found no evidence of in-the-wild exploitation, but warned that BTR.sys functions as a built-in signed living-off-the-land driver that is not covered by traditional vulnerable-driver blocklists, increasing the need for behavioral detection and tighter privilege controls.
CISA, the FBI, and HHS issued an updated joint advisory warning that Medusa ransomware operators have compromised more than 500 organizations as of April 2026, with heavy targeting of critical infrastructure and especially healthcare and public health entities. The agencies said the group evolved from a closed operation into a ransomware-as-a-service model in 2023, using double extortion by stealing data before encrypting systems. Officials said Medusa actors can exploit newly disclosed vulnerabilities within 24 hours, and in some cases were observed abusing flaws up to a week before public disclosure. The advisory said Medusa gains access through initial access brokers, reportedly offering up to $1 million for exclusive access, and has exploited vulnerabilities including CVE-2024-1709, CVE-2023-48788, GoAnywhere MFT flaws, and CVE-2026-1731. Once inside, operators use living-off-the-land techniques, credential dumping, stolen or vulnerable drivers, and legitimate remote monitoring and management tools to disable security controls, move laterally, steal sensitive data, and encrypt networks. Authorities also described aggressive extortion tactics such as rapid-payment discounts and paid deadline extensions, while urging organizations to patch quickly, segment networks, enforce phishing-resistant MFA, maintain offline immutable backups, and monitor for unauthorized RMM activity.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.