Skip to content

Mimikatz

Mimikatz is a Windows post-exploitation credential-access tool widely used by penetration testers and threat actors.

Profile source: Mallory opens in a new tab

Mimikatz

Family profile

Mimikatz is a Windows post-exploitation credential-access tool widely used by penetration testers and threat actors. It extracts plaintext credentials, NTLM password hashes, Kerberos tickets, LSA secrets, Security Account Manager data, and other credential material from Windows memory and protected credential stores. Its capabilities support credential dumping from LSASS, extraction of domain and local account secrets, and credential-abuse techniques including Pass-the-Hash, Overpass-the-Hash, and DCSync, enabling lateral movement and domain compromise. Mimikatz has been observed in intrusions involving BISMUTH, Cuba ransomware affiliates, Toy Ghouls, The Gentlemen affiliates, LockBit affiliates, Warlock, Storm-1175, and other financially motivated and espionage-oriented operators. It is generally introduced after an attacker has already obtained access to a Windows environment rather than serving as an initial-access payload.

Capabilities

  • Credential Theft
  • Lateral Movement
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 6, 2026
Last activity
Sep 12, 2026
Feed role
C2 / Distribution
Host form
13 IP / 9 hostnames

Leading locations

  • DE6
  • US6
  • KR4
  • NL3
  • CN2
  • JP1

Leading providers

  • FEMO IT SOLUTIONS LIMITED4
  • SK Broadband Co Ltd3
  • Cloudflare, Inc.2
  • Omegatech LTD2
  • Amazon.com, Inc.1
  • Amazon.com, Inc.1

Infrastructure traits

  • Hosting 16
  • Anycast 2

Samples

Recent associated samples

Reported operators

Threat actors

115 named in public reporting
APT32

"The group used DebugView and the malicious DLL ... to launch Base64-encoded Mimikatz commands" including "sekurlsa::logonpasswords" and "lsadump::lsa /inject."

REF3927

The threat actor created an Administrator account and attempted to dump credentials using Mimikatz, but this was prevented by Elastic Defend.

REF9019

"Mimikatz is an offensive security tool used to collect and inject passwords from compromised systems"; the SEKURLSA::LogonPasswords module was observed.

UTA-2026-024

A separate LSASS memory dump and Mimikatz supplied additional routes to credentials.

Toy Ghouls

Toy Ghouls uses mimikatz to access LSA secrets, extract LSASS data and credentials, and perform Pass-the-Hash, Overpass-the-Hash, and DCSync techniques.

GOLD SHERWOOD

Récupération du PID de LSASS : tasklist /v /fo csv | findstr /i "lsass". Usage de Mimikatz confirmé par des recherches tierces.

INC Ransom affiliate

C:\Users\Public\mimi.exe is listed as a Mimikatz path explicitly checked by the affiliate's credential-harvesting script.

Play

The following TTPs and IOCs have been published by multiple researchers ... TA0006 - Credential Access Mimikatz.

Storm-1175

The group is using AnyDesk or SimpleHelp, Advanced IP Scanner for reconnaissance, and Mimikatz to dump credentials from the LSASS process.

Water Manaul

Previous research indicates that the threat actors employed Mimikatz and registry hive dumping.

Volt Typhoon

User credentials are gained through a variety of different means including exploitation of public-facing appliances, insecurely stored credentials, extracting the Active Directory database file (NTDS.dit), enumerating existing stored sessions, credential dumping through LSASS, and use of the Mimikatz and Impacket tools

HEXANE

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.

BRONZE BUTLER

BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB

menuPass

menuPass has used DLL side-loading to launch versions of Mimikatz and PwDump6 as well as UPPERCUT.

OilRig

Mimikatz – an open source tool designed to extract and use credential information from Windows systems

APT39

Chafer has also continued to use tools previously associated with the group, including its own custom backdoor Remexi; the aforementioned PsExec; Mimikatz (Hacktool.Mimikatz), a free tool capable of changing privileges, exporting security certificates, and recovering Windows passwords in plaintext.

APT3

The system stealer attempts to obtain credentials from LSASS with a technique similar to that used by Mimikatz.

Threat Group-3390

In order to stealth authentication materials on compromised hosts, adversaries relied on the mimikatz tool.

Fox Kitten

This was performed using several open-source utilities, including nanodump and mimikatz.

CryptoCore

However, in singular cases we have seen the group downloading and using the Mimikatz password-dumping tool as well... During the attack, we suspect the group also employing Mimikatz for credentials harvesting.

Chernovite

Using DUSTTUNNEL's command-and-control functions, CHERNOVITE could drop additional tools such as Mimikatz to gather credentials to access a legitimate account and gain a persistent foothold in the enterprise network.

Kimsuky

The group also installs Mimikatz and RDP Wrapper, which have both been steadily used for many years.

LAPSUS$

The group used DCSync attacks and Mimikatz to perform privilege escalation routines.

Lazarus

The Variations in the playbook ... Credential harvesting using tools such as Mimikatz and Procdump.

MuddyWater

MuddyWaters uses different types of attacks for initial access like phishing email campaigns, using tools like MimiKatz to break into the system, etc.

A41APT

Following tools were found in the lateral movement stage â—‹ Mimikatz â—‹ secretdump.py â—‹ PsExec â—‹ csvde â—‹ WinRAR

Antlion

Kerberos golden ticket tool based on the Mimikatz credentials stealer

mallox

The threat actor used Mimikatz to dump the credentials on the server they gained their initial access on.

HAFNIUM

The attackers used CobaltStrike, which was downloaded to the victim’s computer using the certutil.exe utility, compiled aspx webshells, the procdump tool, and Mimikatz.

APT41

32- and 64-bit signed builds of this password dumper were also found among several victims compromised by Winnti variants installed from the Install.exe dropper, sometimes in conjunction with Mimikatz.

RomCom

Additional activity related to credential theft was observed approximately one week after the use of GetUserSPNs.ps1, with the observation of Mimikatz on a user's workstation being written into the user’s document folder as a zipped file.

APT28

Lors de réponses à incident, l’ANSSI a pu confirmer l’utilisation des outils malveillants Mimikatz et reGeorg par APT28 : • Mimikatz est un outil qui peut notamment servir à extraire les mots de passe (ou leurs empreintes) stockés en mémoire sous Windows;

Ke3chang

Playful Taurus used Mimikatz to dump credentials and generate Kerberos Golden Tickets.

APT33

Symantec has the following protection in place to protect customers against Elfin attacks: ... Hacktool.Mimikatz ... Symantec has the following protection in place to protect customers against Chafer attacks: ... Hacktool.Mimikatz ...

panda

This includes the credential-theft tool Mimikatz and UPX-packed artifacts related to the Equation Group set of exploits.

Greenbug

Shortly after this, the well-known credential-stealing tool Mimikatz was executed from %USERPROFILE%\documents\x64.

APT29

these modules, loaded by operators at completely random or sporadic moments during malware execution, are part of the Mimikatz tool. In other words, in order to evade behavioral signatures and avoid detection, attackers have “chopped up” the aforementioned tool using only the logic of the DCSYNC attack.

CL-STA-1062

Among the open-source tools frequently utilized are SoftEther VPN for secure communications, Mimikatz for credential harvesting, and VNT for network traversal.

Hyadina

With the defenses lowered, the attackers installed tools including NirSoft and Mimikatz, which are used to steal credentials, cookies, live network traffic and more, with the aim of finding means to gain further control over the machine and the wider network, including administrator accounts.

Larva-26009

Additionally, Mimikatz, the Fscan scanner, the gost proxy, and the user account creation tool can be used as plugins.

Qilin

Mimikatz — dump de credentials en mémoire

Turla

Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.

Red Menshen

During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.

UAT-7237

While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.

DragonForce

Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001).

FIN7

FIN7 and Carbanak abused ProcDump to dump LSASS memory â–¸ PowerShell Mimikatz scripts also widely used

Carbanak

FIN7 and Carbanak abused ProcDump to dump LSASS memory â–¸ PowerShell Mimikatz scripts also widely used

Makop

Along with the classical abuse of Microsoft SysInternal tools such as PsExec and other well-known open-source tools such as Putty and the never-missing Mimikatz, during recent operations, Makop abused even more peculiar software.

APT Chimera

A customized modification of the original Mimikatz, Mimikat.dll was designed to specifically inject the Skeleton Key to allow the attackers persistent, unfettered Lateral Movement across the network.

Scattered Spider

Additional tradecraft and techniques: Using open-source tooling: Mimikatz, Hekatomb, Lazagne, gosecretsdump, smbpasswd.py, LinPEAS, ADFSDump.

Twelve

The adversary used mimikatz to obtain user credentials. They saved the utility file under the name calculator.exe to disguise its real purpose.

GALLIUM

For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.

Storm-2603

Microsoft’s profile of the group noted the execution of Mimikatz “specifically targeting the Local Security Authority Subsystem Service (LSASS) memory to extract plaintext credentials.”

Head Mare

The investigation identified tools for obtaining credentials. Besides the publicly available mimikatz utility, the attackers used secretsdump and ProcDump.

Crypt Ghouls

We detected the use of the Mimikatz utility in some of the investigated attacks.

Cobalt Group

Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.

PittyTiger

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Blue Mockingbird

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Chimera

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Handala

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

TA505

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Whitefly

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

DarkHydrus

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

APT38

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

FIN6

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Cleaver

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

FIN13

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Lotus Blossom

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Dragonfly

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

TEMP.Veles

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Leafminer

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Magic Hound

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Lizar

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

WIZARD SPIDER

Before that, however, antivirus on HSE endpoints detected both Cobalt Strike and Mimikatz being deployed on the so-called Patient Zero workstation.

Vanilla Tempest

To laterally move within the target network, Mimikatz was used to dump passwords.

Earth Longzhi

Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."

Shadow-Earth-053

To facilitate privilege escalation, SHADOW-EARTH-053 has been found to use Mimikatz, while lateral movement is accomplished using a custom remote desktop protocol (RDP) launcher and C# implementation of SMBExec known as Sharp-SMBExec.

UNC2447

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

SVR

“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”

slow#tempest

"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."

Yanluowang

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

UNC2717

"...using the credential harvesting tool Mimikatz."

APT5

"...using the credential harvesting tool Mimikatz."

Warlock

Persistence is achieved by emplacement of ASPX webshells that allow execution of Mimikatz for credential recovery.

Mikroceen

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

GreyEnergy

The GreyEnergy group uses fairly standard tools for these tasks: Nmap and Mimikatz.

Calypso

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

Tonto

“The group continues to push various custom Mimikatz variants and keyloggers for credential harvesting purposes…”

Vicious Panda

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

CozyCar

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Andariel

The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.

Conti

...a manual on deploying Cobalt Strike, mimikatz to dump NTLM hashes...

Earth Lusca

Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).

FIN8

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Sandworm

Sandworm Team used UPX to pack a copy of Mimikatz.

Silence

Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.

APT1

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Agrius

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.

Gold Dupont

We identified a different config.dat file being used for different purposes, like information gathering through Pyxie, Lazagne and Mimikatz...

unc215

...an operator repeatedly and infrequently revisited a compromised network whenever an Endpoint Detection and Response (EDR) tool detected or quarantined tools like HYPERBRO and Mimikatz.

APT6

"A modified mimikatz which extracts passwords from memory."

TAC5279

"...immediately executed a Zerologon exploit against the organization’s domain controller using the Mimikatz tool."

Stonefly/Clasiopa

The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.

Storm-0501

The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer

Mustang Panda

The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer

Flax Typhoon

The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.

CL-STA-1087

Attackers also used Getpass, a custom Mimikatz DLL, masquerading as a Palo Alto tool, which automatically harvests credentials from 10 Windows authentication packages by accessing lsass.exe memory.

CL-UNK-1068

Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.

UNC1945

"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."

Contagious Interview

Microsoft Defender Antivirus detects threat components as ... HackTool:Win32/Mimikatz ... HackTool:Win64/Mimikatz

TraderTraitor

"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."

Exploited software

Vulnerabilities linked to Mimikatz

20 CVEs

MITRE ATT&CK

Mimikatz in ATT&CK

67 distinct techniques

Techniques

67 techniques
T1550.002 Pass the Hash T1550.003 Pass the Ticket T1003.001 LSASS Memory T1003 OS Credential Dumping T1562.001 Disable or Modify Tools T1003.004 LSA Secrets T1588.002 Tool T1074.001 Local Data Staging T1003.002 Security Account Manager T1003.003 NTDS T1003.006 DCSync T1057 Process Discovery T1106 Native API T1003.005 Cached Domain Credentials T1190 Exploit Public-Facing Application T1548.002 Bypass User Account Control T1068 Exploitation for Privilege Escalation T1059.001 PowerShell T1556 Modify Authentication Process T1558.001 Golden Ticket T1218 System Binary Proxy Execution T1078 Valid Accounts T1558 Steal or Forge Kerberos Tickets T1074 Data Staged T1550 Use Alternate Authentication Material T1207 Rogue Domain Controller T1559.001 Component Object Model T1562 Impair Defenses T1555.003 Credentials from Web Browsers T1555 Credentials from Password Stores T1574 Hijack Execution Flow T1055 Process Injection T1070.004 File Deletion T1620 Reflective Code Loading T1021 Remote Services T1105 Ingress Tool Transfer T1036 Masquerading T1134 Access Token Manipulation T1543 Create or Modify System Process T1649 Steal or Forge Authentication Certificates T1047 Windows Management Instrumentation T1574.001 DLL T1484.001 Group Policy Modification T1570 Lateral Tool Transfer T1087 Account Discovery T1059 Command and Scripting Interpreter T1134.005 SID-History Injection T1127 Trusted Developer Utilities Proxy Execution T1027 Obfuscated Files or Information T1140 Deobfuscate/Decode Files or Information T1021.001 Remote Desktop Protocol T1552 Unsecured Credentials T1098 Account Manipulation T1059.003 Windows Command Shell T1136 Create Account T1033 System Owner/User Discovery T1560 Archive Collected Data T1055.002 Portable Executable Injection T1563.002 RDP Hijacking T1112 Modify Registry T1046 Network Service Discovery T1082 System Information Discovery T1219 Remote Access Tools T1021.002 SMB/Windows Admin Shares T1110 Brute Force T1608.002 Upload Tool T1040 Network Sniffing

Reporting

Research mentioning Mimikatz

Aug 20
Cyber Security News

Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel

Check Point Research reported that Microsoft’s Windows Defender Boot-Time Removal driver, BTR.sys, can be repurposed as a Microsoft-signed kernel-mode primitive for arbitrary file and registry operations. After reverse engineering the driver, the researcher documented its RC4-encrypted transaction format and integrity checks, then built a proof-of-concept tool, BTR_CLI, that generates valid transactions, stages the driver, and executes actions on systems ranging from Windows 7 through Windows 11. The report says the driver’s legitimate remediation capability could let an attacker abuse a boot-time “golden window” to bypass or weaken EDR and antivirus protections before higher-level defenses fully initialize, including deleting Defender binaries and modifying protected registry keys. Check Point said it found no evidence of in-the-wild exploitation, but warned that BTR.sys functions as a built-in signed living-off-the-land driver that is not covered by traditional vulnerable-driver blocklists, increasing the need for behavioral detection and tighter privilege controls.

Aug 20
Checkpoint Research

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive - Check Point Research

Aug 19
Bleeping Computer

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

CISA, the FBI, and HHS issued an updated joint advisory warning that Medusa ransomware operators have compromised more than 500 organizations as of April 2026, with heavy targeting of critical infrastructure and especially healthcare and public health entities. The agencies said the group evolved from a closed operation into a ransomware-as-a-service model in 2023, using double extortion by stealing data before encrypting systems. Officials said Medusa actors can exploit newly disclosed vulnerabilities within 24 hours, and in some cases were observed abusing flaws up to a week before public disclosure. The advisory said Medusa gains access through initial access brokers, reportedly offering up to $1 million for exclusive access, and has exploited vulnerabilities including CVE-2024-1709, CVE-2023-48788, GoAnywhere MFT flaws, and CVE-2026-1731. Once inside, operators use living-off-the-land techniques, credential dumping, stolen or vulnerable drivers, and legitimate remote monitoring and management tools to disable security controls, move laterally, steal sensitive data, and encrypt networks. Authorities also described aggressive extortion tactics such as rapid-payment discounts and paid deadline extensions, while urging organizations to patch quickly, segment networks, enforce phishing-resistant MFA, maintain offline immutable backups, and monitor for unauthorized RMM activity.

Aug 18
Malware News

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics - Malware News - Malware Analysis, News and Indicators

Aug 18
Data Breaches

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics - DataBreaches.Net

Aug 18
The Record Media

More than 200 victims of Medusa ransomware identified over the last year, CISA says | The Record from Recorded Future News

Aug 18
Cyber Security News

CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.