Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 30, 2026
- Feed role
- C2 / Distribution
- Host form
- 18 IP / 9 hostnames
Mimikatz is a widely used Windows post-exploitation tool focused on credential access and abuse of Windows authentication mechanisms.
Profile source: Mallory opens in a new tabMimikatz
Mimikatz is a widely used Windows post-exploitation tool focused on credential access and abuse of Windows authentication mechanisms. Originally developed by Benjamin Delpy with contributions from Vincent Le Toux, it became a standard utility in both offensive security operations and real intrusions for extracting credentials and authentication material from compromised systems. Its capabilities include dumping memory-resident credentials from LSASS, recovering cached credentials, extracting Kerberos tickets, and obtaining password hashes and other secrets that can be used for follow-on compromise.
Mimikatz is frequently deployed after initial compromise by ransomware operators, espionage actors, and intrusion sets seeking to expand access inside enterprise Windows environments. Reported use spans financially motivated campaigns and state-linked operations, including activity associated with groups such as Turla and intrusions involving Qilin and DragonForce-related operators. It is commonly paired with lateral movement tooling and remote administration utilities once attackers have established a foothold.
A notable capability is DCSync through the lsadump::dcsync module, which abuses legitimate Active Directory replication mechanisms to request account secrets remotely when the attacker controls an identity with replication privileges. This enables retrieval of NTLM hashes, Kerberos keys, and password history without interactively logging onto a domain controller or copying the directory database from disk. Theft of highly privileged secrets such as the krbtgt account can enable persistent domain-wide compromise through forged Kerberos tickets.
Mimikatz is primarily associated with Windows environments and is most often used during credential theft, privilege escalation, and lateral movement phases of an intrusion. It remains one of the most recognizable credential-dumping tools in the ecosystem and is routinely incorporated into attacker playbooks, red-team operations, and malware deployment chains as a plugin or auxiliary utility.
C2 tracking
Derp observations, rolling seven-day window
Samples
033de4a337484f7a0d2fbf8cb76f7812e6053968c845b1ff1ad16ec825feefb5 79ed1c370bc7059ad7399ea790e28830d44bac5f19fe93db032792ca5de1917c 7d5f00d87d9126043a4cc28271da717eefb81d78b03b9bfdc8d0dfbb51be7f98 f1f247857acb332e4d931985612215b04e5021322861f5cbe0a50792795a8ed6 faf9e97153bb9d5221b383b57d8708bd898d0c8a706fc2ba3c33fa5848ccbc1d 1f49316f60cee5fd365ecda4b1c43fcfe10ec5a52fd0721b4eeb811afeab77ba 4c0d2372f3d03a95fae67956989fbc9e307b318c5551f74a48c2b850d55bb169 cb8d68041200958ef7c8b1c5d5cb82c2545f2d89b67dd49c564242f2f009362c d35d30ccc119aacab7cbf48fdddb54a9149507f79e99d102e37b43958e80e835 fe2df8d60de416b5347dc1cc3522579db1e19b1daf38c931978ac36b95ca2aba Reported operators
Additionally, Mimikatz, the Fscan scanner, the gost proxy, and the user account creation tool can be used as plugins.
Mimikatz — dump de credentials en mémoire
The remaining tool, Mimikatz, is widely known for extracting credentials and authentication material from Windows systems and is frequently abused during post-compromise activity.
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001).
FIN7 and Carbanak abused ProcDump to dump LSASS memory ▸ PowerShell Mimikatz scripts also widely used
FIN7 and Carbanak abused ProcDump to dump LSASS memory ▸ PowerShell Mimikatz scripts also widely used
Along with the classical abuse of Microsoft SysInternal tools such as PsExec and other well-known open-source tools such as Putty and the never-missing Mimikatz, during recent operations, Makop abused even more peculiar software.
A customized modification of the original Mimikatz, Mimikat.dll was designed to specifically inject the Skeleton Key to allow the attackers persistent, unfettered Lateral Movement across the network.
Additional tradecraft and techniques: Using open-source tooling: Mimikatz, Hekatomb, Lazagne, gosecretsdump, smbpasswd.py, LinPEAS, ADFSDump.
In this campaign, the attackers are also seen dumping credentials, including by using a custom Mimikatz loader. This version of Mimikatz drops mimilib.dll to obtain credentials in plain text for any user that is accessing the compromised host and provides persistence across reboots.
The adversary used mimikatz to obtain user credentials. They saved the utility file under the name calculator.exe to disguise its real purpose.
For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.
Microsoft’s profile of the group noted the execution of Mimikatz “specifically targeting the Local Security Authority Subsystem Service (LSASS) memory to extract plaintext credentials.”
The investigation identified tools for obtaining credentials. Besides the publicly available mimikatz utility, the attackers used secretsdump and ProcDump.
The attackers also used Mimikatz to dump account credentials. Like the Pillager stealer, Mimikatz was rewritten and compiled into a DLL.
For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.
We detected the use of the Mimikatz utility in some of the investigated attacks.
The toolkit was unchanged: X-Agent for keylogging and screenshotting, X-Tunnel for exfiltration, Mimikatz for credential theft.
Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
The hackers used well known tools, including Meterpreter, Mimikatz, Lazagne, Invoke-Obfuscation, and more.
Before that, however, antivirus on HSE endpoints detected both Cobalt Strike and Mimikatz being deployed on the so-called Patient Zero workstation.
The timeline, which was seemingly produced by security investigators at Mandiant or based on data gathered by the firm, shows that the Lapsus$ group was able to use extremely well known and widely available hacking tools, like the password-grabbing tool Mimikatz, to rampage through Sitel's systems.
Mimikatz (Hacktool.Mimikatz): Tool designed to steal credentials
To laterally move within the target network, Mimikatz was used to dump passwords.
Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."
To facilitate privilege escalation, SHADOW-EARTH-053 has been found to use Mimikatz, while lateral movement is accomplished using a custom remote desktop protocol (RDP) launcher and C# implementation of SMBExec known as Sharp-SMBExec.
Impacket is further used to facilitate credential dumping through LSASS; the threat actor also leveraged the commodity credential theft tool Mimikatz in identified intrusions in 2025.
"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."
"It also uses two custom versions of Mimikatz..."
“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”
"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."
"...other tools including Mimikatz..."
"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."
“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”
"...using the credential harvesting tool Mimikatz."
"...using the credential harvesting tool Mimikatz."
Persistence is achieved by emplacement of ASPX webshells that allow execution of Mimikatz for credential recovery.
...use Mimikatz to harvest credentials...
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
The GreyEnergy group uses fairly standard tools for these tasks: Nmap and Mimikatz.
"Pypykatz (a Python version of Mimikatz)"
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
“The group continues to push various custom Mimikatz variants and keyloggers for credential harvesting purposes…”
Asking for an alternative application to mimikatz.
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.
...a manual on deploying Cobalt Strike, mimikatz to dump NTLM hashes...
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
Sandworm Team used UPX to pack a copy of Mimikatz.
Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.
We identified a different config.dat file being used for different purposes, like information gathering through Pyxie, Lazagne and Mimikatz...
...an operator repeatedly and infrequently revisited a compromised network whenever an Endpoint Detection and Response (EDR) tool detected or quarantined tools like HYPERBRO and Mimikatz.
"A modified mimikatz which extracts passwords from memory."
"...immediately executed a Zerologon exploit against the organization’s domain controller using the Mimikatz tool."
The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.
we also observed Mimikatz... uses the SEKURLSA::LogonPasswords module
One is “CreateMimi1Bat”; which likely executes Mimikatz (executes PowerShell scripts: ccd61.ps1 and Invoke-bypassuac), according to Arbor.
The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
By abusing legitimate tools such as Cobalt Strike, Mimikatz, ProcDump, AdFind, and WinPEAS, the group conducts credential theft, privilege escalation, lateral movement, and data exfiltration.
The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.
Attackers also used Getpass, a custom Mimikatz DLL, masquerading as a Palo Alto tool, which automatically harvests credentials from 10 Windows authentication packages by accessing lsass.exe memory.
The Lazarus Group's Medusa ransomware campaign includes the use of various tools - RP_Proxy, a custom proxy utility Mimikatz, a publicly available credential dumping program Comebacker, a custom backdoor exclusively used by the threat actor InfoHook, an information stealer previously identified as used in conjunction with Comebacker BLINDINGCAN (aka AIRDRY or ZetaNile), a remote access trojan ChromeStealer, a tool for extracting stored passwords from the Chrome browser.
Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.
"UNC2596 leveraged credential theft tools such as Mimikatz and WICKER."
"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."
"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."
Additional Credential Theft... mimikatz.exe
“CHERNOVITE could drop additional tools, such as Mimikatz, to gather credentials…”
Exploited software
MITRE ATT&CK
Reporting
A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.
Recovered eDiary files and related forensic evidence have been cited as linking APT15 activity to the PLA Cyberspace Force’s 8th Technical Reconnaissance Base, also known as Unit 61046. Reporting says the material contains operational notes, exploit logs, victim research, mailbox screenshots, and stolen credentials tied to multiple government targets, including the Royal Thailand Armed Forces. Searches for terms associated with APT15, particularly vpnkerio, reportedly produced matches in the same diary data that referenced the 8th TRB, strengthening claims that the group’s infrastructure, targeting, and tradecraft overlap with a Chinese military unit. The intrusion workflow described in the recovered records aligns with previously documented APT15 tactics, including exploitation of CVE-2020-0688 against Microsoft Exchange. According to the reporting, attackers used a Python-based exploit chain to redirect victims to infrastructure associated with vpnkerio[.]com, deliver kerio.exe, and install a webshell for follow-on access. The combined evidence has been presented as support for attributing APT15 operations to a PLA espionage organization rather than to loosely affiliated contractors or purely commercial operators.
The ransomware group INC Ransom has been linked to an attack on takethehop.com, the website of The HOP, a regional public transit system operated by the Hill Country Transit District in Texas. The incident was reported as a data breach and ransomware event, adding a public-sector transportation victim to the group’s growing list of targets as double-extortion campaigns continue to hit North American organizations. MITRE ATT&CK describes INC Ransom as an intrusion set that commonly gains access through phishing, compromised valid accounts, and exploitation of public-facing applications including CVE-2023-3519 in Citrix NetScaler, then conducts discovery, lateral movement, data staging, exfiltration, and encryption. The group has been observed using tools such as AnyDesk, PuTTY, PsExec, MegaSync, Advanced IP Scanner, WMIC, 7-Zip, and WinRAR, while disguising activity and disabling defenses before deploying ransomware. A recent Cyble global threat report also identified INC Ransom among the major ransomware actors active in 2026, underscoring the continued scale of double-extortion operations worldwide.
Bitdefender disclosed that attackers can abuse Windows bind links to create conflicting filesystem views that let malware appear benign to endpoint detection and response tools while executing attacker-controlled content. The researchers described three variants—file-binding, process-binding, and silo-binding—that redirect trusted paths to malicious files, potentially undermining path-based trust decisions, suppressing AMSI visibility, and concealing offensive tools such as Mimikatz from security products. Microsoft documentation on Sysmon remains relevant for defenders seeking deeper Windows telemetry, but Microsoft reportedly rated the bind-link issue as low severity because exploitation requires local administrator privileges. Bitdefender argued that this prerequisite does not meaningfully reduce risk in real intrusions, where attackers and ransomware operators frequently gain elevated access before moving to defense evasion and persistence.
CISA and Microsoft warned that multiple on-premises SharePoint Server vulnerabilities are being actively exploited against internet-facing systems, with attackers using a chain involving CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to gain unauthorized access, execute code, steal IIS and ASP.NET machine keys, maintain persistence, and deploy malware. The agencies said the activity affects supported on-premises SharePoint deployments rather than SharePoint Online, and follows earlier Microsoft reporting that Chinese threat actors including Linen Typhoon, Violet Typhoon, and Storm-2603 had abused similar SharePoint flaws to install web shells, dump credentials, move laterally, and in some cases deploy Warlock ransomware. Microsoft’s July 2026 updates also fixed two additional critical SharePoint bugs, CVE-2026-55040 and CVE-2026-58644, which were not yet confirmed as exploited but were assessed as likely targets for rapid weaponization, while separate reporting said another SharePoint exploit chain may remain unpatched pending a later release. Defenders were urged to immediately apply available patches, enable AMSI in Full Mode, reduce or remove internet exposure, restrict access to SharePoint Central Administration, review logs and endpoint telemetry for compromise, and only rotate IIS or ASP.NET machine keys after confirming whether intrusion activity is already present.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.