Skip to content

Mimikatz

Mimikatz is a widely used Windows post-exploitation tool focused on credential access and abuse of Windows authentication mechanisms.

Profile source: Mallory opens in a new tab

Mimikatz

Family profile

Mimikatz is a widely used Windows post-exploitation tool focused on credential access and abuse of Windows authentication mechanisms. Originally developed by Benjamin Delpy with contributions from Vincent Le Toux, it became a standard utility in both offensive security operations and real intrusions for extracting credentials and authentication material from compromised systems. Its capabilities include dumping memory-resident credentials from LSASS, recovering cached credentials, extracting Kerberos tickets, and obtaining password hashes and other secrets that can be used for follow-on compromise.

Mimikatz is frequently deployed after initial compromise by ransomware operators, espionage actors, and intrusion sets seeking to expand access inside enterprise Windows environments. Reported use spans financially motivated campaigns and state-linked operations, including activity associated with groups such as Turla and intrusions involving Qilin and DragonForce-related operators. It is commonly paired with lateral movement tooling and remote administration utilities once attackers have established a foothold.

A notable capability is DCSync through the lsadump::dcsync module, which abuses legitimate Active Directory replication mechanisms to request account secrets remotely when the attacker controls an identity with replication privileges. This enables retrieval of NTLM hashes, Kerberos keys, and password history without interactively logging onto a domain controller or copying the directory database from disk. Theft of highly privileged secrets such as the krbtgt account can enable persistent domain-wide compromise through forged Kerberos tickets.

Mimikatz is primarily associated with Windows environments and is most often used during credential theft, privilege escalation, and lateral movement phases of an intrusion. It remains one of the most recognizable credential-dumping tools in the ecosystem and is routinely incorporated into attacker playbooks, red-team operations, and malware deployment chains as a plugin or auxiliary utility.

Capabilities

  • Credential Theft
  • Lateral Movement
  • Post Exploitation
  • Privilege Escalation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 23, 2026
Last activity
Jul 30, 2026
Feed role
C2 / Distribution
Host form
18 IP / 9 hostnames

Leading locations

  • NL6
  • US6
  • CN5
  • DE2
  • DK1
  • GB1
  • HK1
  • IR1
  • JP1
  • KR1
  • LU1
  • SG1

Leading providers

  • Hangzhou Alibaba Advertising Co.,Ltd.3
  • Developed Methods LLC2
  • FEMO IT SOLUTIONS LIMITED2
  • Amazon.com, Inc.1
  • Amazon.com, Inc.1
  • Baykov Ilya Sergeevich1

Infrastructure traits

  • Hosting 21
  • Anycast 2
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

100 named in public reporting
Larva-26009

Additionally, Mimikatz, the Fscan scanner, the gost proxy, and the user account creation tool can be used as plugins.

Qilin

Mimikatz — dump de credentials en mémoire

Hyadina

The remaining tool, Mimikatz, is widely known for extracting credentials and authentication material from Windows systems and is frequently abused during post-compromise activity.

Turla

Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.

Red Menshen

During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.

CL-STA-1062

While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.

UAT-7237

While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.

DragonForce

Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001).

FIN7

FIN7 and Carbanak abused ProcDump to dump LSASS memory ▸ PowerShell Mimikatz scripts also widely used

Carbanak

FIN7 and Carbanak abused ProcDump to dump LSASS memory ▸ PowerShell Mimikatz scripts also widely used

Makop

Along with the classical abuse of Microsoft SysInternal tools such as PsExec and other well-known open-source tools such as Putty and the never-missing Mimikatz, during recent operations, Makop abused even more peculiar software.

APT Chimera

A customized modification of the original Mimikatz, Mimikat.dll was designed to specifically inject the Skeleton Key to allow the attackers persistent, unfettered Lateral Movement across the network.

Scattered Spider

Additional tradecraft and techniques: Using open-source tooling: Mimikatz, Hekatomb, Lazagne, gosecretsdump, smbpasswd.py, LinPEAS, ADFSDump.

menuPass

In this campaign, the attackers are also seen dumping credentials, including by using a custom Mimikatz loader. This version of Mimikatz drops mimilib.dll to obtain credentials in plain text for any user that is accessing the compromised host and provides persistence across reboots.

Twelve

The adversary used mimikatz to obtain user credentials. They saved the utility file under the name calculator.exe to disguise its real purpose.

GALLIUM

For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.

Storm-2603

Microsoft’s profile of the group noted the execution of Mimikatz “specifically targeting the Local Security Authority Subsystem Service (LSASS) memory to extract plaintext credentials.”

Head Mare

The investigation identified tools for obtaining credentials. Besides the publicly available mimikatz utility, the attackers used secretsdump and ProcDump.

APT41

The attackers also used Mimikatz to dump account credentials. Like the Pillager stealer, Mimikatz was rewritten and compiled into a DLL.

Threat Group-3390

For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.

Crypt Ghouls

We detected the use of the Mimikatz utility in some of the investigated attacks.

APT28

The toolkit was unchanged: X-Agent for keylogging and screenshotting, X-Tunnel for exfiltration, Mimikatz for credential theft.

Cobalt Group

Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.

BRONZE BUTLER

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

PittyTiger

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Blue Mockingbird

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Chimera

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Handala

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

TA505

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Kimsuky

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Whitefly

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

APT32

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

DarkHydrus

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

APT38

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

FIN6

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Cleaver

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

FIN13

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Lotus Blossom

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

OilRig

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

HEXANE

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Dragonfly

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

APT39

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

TEMP.Veles

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Leafminer

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Ke3chang

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Magic Hound

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Lizar

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

MuddyWater

The hackers used well known tools, including Meterpreter, Mimikatz, Lazagne, Invoke-Obfuscation, and more.

WIZARD SPIDER

Before that, however, antivirus on HSE endpoints detected both Cobalt Strike and Mimikatz being deployed on the so-called Patient Zero workstation.

LAPSUS$

The timeline, which was seemingly produced by security investigators at Mandiant or based on data gathered by the firm, shows that the Lapsus$ group was able to use extremely well known and widely available hacking tools, like the password-grabbing tool Mimikatz, to rampage through Sitel's systems.

APT33

Mimikatz (Hacktool.Mimikatz): Tool designed to steal credentials

Vanilla Tempest

To laterally move within the target network, Mimikatz was used to dump passwords.

Earth Longzhi

Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."

Shadow-Earth-053

To facilitate privilege escalation, SHADOW-EARTH-053 has been found to use Mimikatz, while lateral movement is accomplished using a custom remote desktop protocol (RDP) launcher and C# implementation of SMBExec known as Sharp-SMBExec.

Storm-1175

Impacket is further used to facilitate credential dumping through LSASS; the threat actor also leveraged the commodity credential theft tool Mimikatz in identified intrusions in 2025.

UNC2447

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

SVR

“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”

slow#tempest

"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."

Yanluowang

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

APT29

“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”

UNC2717

"...using the credential harvesting tool Mimikatz."

APT5

"...using the credential harvesting tool Mimikatz."

Warlock

Persistence is achieved by emplacement of ASPX webshells that allow execution of Mimikatz for credential recovery.

REF3927

...use Mimikatz to harvest credentials...

Mikroceen

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

GreyEnergy

The GreyEnergy group uses fairly standard tools for these tasks: Nmap and Mimikatz.

Calypso

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

Tonto

“The group continues to push various custom Mimikatz variants and keyloggers for credential harvesting purposes…”

ViciousPanda

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

CozyCar

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Andariel

The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.

Conti

...a manual on deploying Cobalt Strike, mimikatz to dump NTLM hashes...

FIN8

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Sandworm

Sandworm Team used UPX to pack a copy of Mimikatz.

Silence

Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.

APT1

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Agrius

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.

Gold Dupont

We identified a different config.dat file being used for different purposes, like information gathering through Pyxie, Lazagne and Mimikatz...

unc215

...an operator repeatedly and infrequently revisited a compromised network whenever an Endpoint Detection and Response (EDR) tool detected or quarantined tools like HYPERBRO and Mimikatz.

APT6

"A modified mimikatz which extracts passwords from memory."

TAC5279

"...immediately executed a Zerologon exploit against the organization’s domain controller using the Mimikatz tool."

Stonefly/Clasiopa

The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.

REF9019

we also observed Mimikatz... uses the SEKURLSA::LogonPasswords module

Greenbug

One is “CreateMimi1Bat”; which likely executes Mimikatz (executes PowerShell scripts: ccd61.ps1 and Invoke-bypassuac), according to Arbor.

Storm-0501

The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer

Mustang Panda

The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer

Play

By abusing legitimate tools such as Cobalt Strike, Mimikatz, ProcDump, AdFind, and WinPEAS, the group conducts credential theft, privilege escalation, lateral movement, and data exfiltration.

Flax Typhoon

The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.

CL-STA-1087

Attackers also used Getpass, a custom Mimikatz DLL, masquerading as a Palo Alto tool, which automatically harvests credentials from 10 Windows authentication packages by accessing lsass.exe memory.

Lazarus

The Lazarus Group's Medusa ransomware campaign includes the use of various tools - RP_Proxy, a custom proxy utility Mimikatz, a publicly available credential dumping program Comebacker, a custom backdoor exclusively used by the threat actor InfoHook, an information stealer previously identified as used in conjunction with Comebacker BLINDINGCAN (aka AIRDRY or ZetaNile), a remote access trojan ChromeStealer, a tool for extracting stored passwords from the Chrome browser.

CL-UNK-1068

Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.

RomCom

"UNC2596 leveraged credential theft tools such as Mimikatz and WICKER."

UNC1945

"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."

TraderTraitor

"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."

Chernovite

“CHERNOVITE could drop additional tools, such as Mimikatz, to gather credentials…”

Exploited software

Vulnerabilities linked to Mimikatz

16 CVEs

MITRE ATT&CK

Mimikatz in ATT&CK

77 distinct techniques

Techniques

77 techniques
T1555 Credentials from Password Stores T1003 OS Credential Dumping T1003.006 DCSync T1562 Impair Defenses T1489 Service Stop T1003.001 LSASS Memory T1105 Ingress Tool Transfer T1021 Remote Services T1059 Command and Scripting Interpreter T1565.001 Stored Data Manipulation T1078 Valid Accounts T1649 Steal or Forge Authentication Certificates T1068 Exploitation for Privilege Escalation T1134 Access Token Manipulation T1021.001 Remote Desktop Protocol T1036 Masquerading T1550.002 Pass the Hash T1562.001 Disable or Modify Tools T1059.005 Visual Basic T1620 Reflective Code Loading T1059.001 PowerShell T1055 Process Injection T1070.004 File Deletion T1550.003 Pass the Ticket T1556.001 Domain Controller Authentication T1550 Use Alternate Authentication Material T1074.001 Local Data Staging T1027 Obfuscated Files or Information T1070 Indicator Removal T1003.003 NTDS T1574.001 DLL T1003.002 Security Account Manager T1078.002 Domain Accounts T1003.004 LSA Secrets T1484.001 Group Policy Modification T1548 Abuse Elevation Control Mechanism T1570 Lateral Tool Transfer T1558.001 Golden Ticket T1558 Steal or Forge Kerberos Tickets T1134.001 Token Impersonation/Theft T1140 Deobfuscate/Decode Files or Information T1497 Virtualization/Sandbox Evasion T1558.003 Kerberoasting T1027.010 Command Obfuscation T1547 Boot or Logon Autostart Execution T1112 Modify Registry T1190 Exploit Public-Facing Application T1558.002 Silver Ticket T1556 Modify Authentication Process T1552.001 Credentials In Files T1222 File and Directory Permissions Modification T1608.002 Upload Tool T1083 File and Directory Discovery T1553.002 Code Signing T1569.002 Service Execution T1210 Exploitation of Remote Services T1059.003 Windows Command Shell T1204.002 Malicious File T1588.002 Tool T1005 Data from Local System T1555.004 Windows Credential Manager T1555.003 Credentials from Web Browsers T1059.007 JavaScript T1047 Windows Management Instrumentation T1212 Exploitation for Credential Access T1218.013 Mavinject T1021.002 SMB/Windows Admin Shares T1036.005 Match Legitimate Resource Name or Location T1055.001 Dynamic-link Library Injection T1547.005 Security Support Provider T1129 Shared Modules T1218 System Binary Proxy Execution T1014 Rootkit T1543.003 Windows Service T1558.004 AS-REP Roasting T1003.005 Cached Domain Credentials T1211 Exploitation for Defense Evasion

Reporting

Research mentioning Mimikatz

Jul 29
Malware News

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - Malware Analysis - Malware Analysis, News and Indicators

A targeted attack on an MS-SQL server led to the deployment of XMRig CoinMiner along with multiple remote-access tools, according to AhnLab ASEC. The intrusion was attributed to the Larva-26009 threat actor, which went beyond the common pattern of opportunistic cryptomining on exposed SQL servers by also installing VShell, GotoHTTP, and SoftEther VPN to maintain control over the compromised system. The toolset indicates the attackers sought both monetization and persistent remote administration after the initial compromise. While coin miners are frequently observed in attacks against internet-exposed Microsoft SQL Server instances, the addition of tunneling and remote-management software suggests a more deliberate post-compromise operation designed to preserve access and expand attacker control over the victim environment.

Jul 28
Malware News

Turns out the Ghost was the PLA - Malware News - Malware Analysis, News and Indicators

Recovered eDiary files and related forensic evidence have been cited as linking APT15 activity to the PLA Cyberspace Force’s 8th Technical Reconnaissance Base, also known as Unit 61046. Reporting says the material contains operational notes, exploit logs, victim research, mailbox screenshots, and stolen credentials tied to multiple government targets, including the Royal Thailand Armed Forces. Searches for terms associated with APT15, particularly vpnkerio, reportedly produced matches in the same diary data that referenced the 8th TRB, strengthening claims that the group’s infrastructure, targeting, and tradecraft overlap with a Chinese military unit. The intrusion workflow described in the recovered records aligns with previously documented APT15 tactics, including exploitation of CVE-2020-0688 against Microsoft Exchange. According to the reporting, attackers used a Python-based exploit chain to redirect victims to infrastructure associated with vpnkerio[.]com, deliver kerio.exe, and install a webshell for follow-on access. The combined evidence has been presented as support for attributing APT15 operations to a PLA espionage organization rather than to loosely affiliated contractors or purely commercial operators.

Jul 27
Hookphish

Ransomware Group incransom Hits: takethehop.com

The ransomware group INC Ransom has been linked to an attack on takethehop.com, the website of The HOP, a regional public transit system operated by the Hill Country Transit District in Texas. The incident was reported as a data breach and ransomware event, adding a public-sector transportation victim to the group’s growing list of targets as double-extortion campaigns continue to hit North American organizations. MITRE ATT&CK describes INC Ransom as an intrusion set that commonly gains access through phishing, compromised valid accounts, and exploitation of public-facing applications including CVE-2023-3519 in Citrix NetScaler, then conducts discovery, lateral movement, data staging, exfiltration, and encryption. The group has been observed using tools such as AnyDesk, PuTTY, PsExec, MegaSync, Advanced IP Scanner, WMIC, 7-Zip, and WinRAR, while disguising activity and disabling defenses before deploying ransomware. A recent Cyble global threat report also identified INC Ransom among the major ransomware actors active in 2026, underscoring the continued scale of double-extortion operations worldwide.

Jul 27
Cyberveille

Rapport Cyble H1 2026 : 3 836 attaques ransomware et paysage cyber mondial en escalade | CyberVeille

Jul 24
Ahnlab Asec

Case Study: Targeted Attack Case on an MS-SQL Server Involving the Installation of GotoHTTP and SoftEther VPN - ASEC

Jul 20
Cyber Security News

Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon

Bitdefender disclosed that attackers can abuse Windows bind links to create conflicting filesystem views that let malware appear benign to endpoint detection and response tools while executing attacker-controlled content. The researchers described three variants—file-binding, process-binding, and silo-binding—that redirect trusted paths to malicious files, potentially undermining path-based trust decisions, suppressing AMSI visibility, and concealing offensive tools such as Mimikatz from security products. Microsoft documentation on Sysmon remains relevant for defenders seeking deeper Windows telemetry, but Microsoft reportedly rated the bind-link issue as low severity because exploitation requires local administrator privileges. Bitdefender argued that this prerequisite does not meaningfully reduce risk in real intrusions, where attackers and ransomware operators frequently gain elevated access before moving to defense evasion and persistence.

Jul 20
Cyber Security News

Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft

CISA and Microsoft warned that multiple on-premises SharePoint Server vulnerabilities are being actively exploited against internet-facing systems, with attackers using a chain involving CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 to gain unauthorized access, execute code, steal IIS and ASP.NET machine keys, maintain persistence, and deploy malware. The agencies said the activity affects supported on-premises SharePoint deployments rather than SharePoint Online, and follows earlier Microsoft reporting that Chinese threat actors including Linen Typhoon, Violet Typhoon, and Storm-2603 had abused similar SharePoint flaws to install web shells, dump credentials, move laterally, and in some cases deploy Warlock ransomware. Microsoft’s July 2026 updates also fixed two additional critical SharePoint bugs, CVE-2026-55040 and CVE-2026-58644, which were not yet confirmed as exploited but were assessed as likely targets for rapid weaponization, while separate reporting said another SharePoint exploit chain may remain unpatched pending a later release. Defenders were urged to immediately apply available patches, enable AMSI in Full Mode, reduce or remove internet exposure, restrict access to SharePoint Central Administration, review logs and endpoint telemetry for compromise, and only rotate IIS or ASP.NET machine keys after confirming whether intrusion activity is already present.

Jul 20
Truesec

Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.