Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 12 IP / 7 hostnames
Mimikatz is a widely used Windows post-exploitation tool focused on credential access and abuse of Windows authentication mechanisms.
Profile source: Mallory opens in a new tabMimikatz
Mimikatz is a widely used Windows post-exploitation tool focused on credential access and abuse of Windows authentication mechanisms. Originally developed by Benjamin Delpy, it is best known for extracting credentials from LSASS memory, recovering plaintext passwords, NTLM hashes, Kerberos tickets, and other authentication material from compromised hosts. It is also commonly used to perform Active Directory replication abuse through its DCSync functionality, allowing operators with sufficient replication privileges to remotely obtain account secrets from domain controllers without directly dumping the NTDS database.
The tool is routinely deployed after initial compromise by a broad range of threat actors, including ransomware operators and state-linked intrusion sets, as part of hands-on-keyboard operations in Windows enterprise environments. Reported use cases include credential dumping from host memory, harvesting cleartext credentials when WDigest or malicious SSP-based logging is enabled, and supporting privilege escalation and lateral movement by enabling follow-on techniques such as pass-the-hash, Kerberos abuse, and domain-wide credential theft. Mimikatz has also been used alongside other post-exploitation tooling for reconnaissance, tunneling, remote administration, and ransomware staging.
Mimikatz targets Windows systems and is especially relevant in domain environments because of its ability to access local credentials and abuse domain replication rights. Its modules and derivatives have made it a standard component of many intrusion playbooks, and its behavior is frequently referenced in detection engineering for credential dumping and related post-compromise activity.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 8e2b78e7c586e36dc3b27c78466fad735f86cdd9b4e7ecbc4c650d934a9a176b b7a06c7dd0943016ee68b5c14ec8a20578df56f9d9fa5f6ea73df6daa5211c07 d00a0806b145423c459a4df53471965dc36f82ec5d5a5d4d108e0a7a1ce09d7b e940830a9e6aa1ca42e80230d076fbc2a7a2ff5c715cc9fb49a061c532562f6f f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f5ebd8f8e5217df1c726beb523c00d49992d6d205589509cbe2c581b6aab29b6 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 93f19b98037d3005850bc4d5382b21e6d242c7759d155e594d1cda3bf128f884 Reported operators
Installation d’outils post-compromission : OpenSSH, socks5.exe, SoftPerfect Network Scanner, Mimikatz
Asking for an alternative application to mimikatz.
Additionally, Mimikatz, the Fscan scanner, the gost proxy, and the user account creation tool can be used as plugins.
Mimikatz — dump de credentials en mémoire
The remaining tool, Mimikatz, is widely known for extracting credentials and authentication material from Windows systems and is frequently abused during post-compromise activity.
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001).
FIN7 and Carbanak abused ProcDump to dump LSASS memory ▸ PowerShell Mimikatz scripts also widely used
FIN7 and Carbanak abused ProcDump to dump LSASS memory ▸ PowerShell Mimikatz scripts also widely used
Along with the classical abuse of Microsoft SysInternal tools such as PsExec and other well-known open-source tools such as Putty and the never-missing Mimikatz, during recent operations, Makop abused even more peculiar software.
A customized modification of the original Mimikatz, Mimikat.dll was designed to specifically inject the Skeleton Key to allow the attackers persistent, unfettered Lateral Movement across the network.
Additional tradecraft and techniques: Using open-source tooling: Mimikatz, Hekatomb, Lazagne, gosecretsdump, smbpasswd.py, LinPEAS, ADFSDump.
In this campaign, the attackers are also seen dumping credentials, including by using a custom Mimikatz loader. This version of Mimikatz drops mimilib.dll to obtain credentials in plain text for any user that is accessing the compromised host and provides persistence across reboots.
The adversary used mimikatz to obtain user credentials. They saved the utility file under the name calculator.exe to disguise its real purpose.
For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.
Microsoft’s profile of the group noted the execution of Mimikatz “specifically targeting the Local Security Authority Subsystem Service (LSASS) memory to extract plaintext credentials.”
The investigation identified tools for obtaining credentials. Besides the publicly available mimikatz utility, the attackers used secretsdump and ProcDump.
The attackers also used Mimikatz to dump account credentials. Like the Pillager stealer, Mimikatz was rewritten and compiled into a DLL.
For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.
We detected the use of the Mimikatz utility in some of the investigated attacks.
The toolkit was unchanged: X-Agent for keylogging and screenshotting, X-Tunnel for exfiltration, Mimikatz for credential theft.
Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
The hackers used well known tools, including Meterpreter, Mimikatz, Lazagne, Invoke-Obfuscation, and more.
Before that, however, antivirus on HSE endpoints detected both Cobalt Strike and Mimikatz being deployed on the so-called Patient Zero workstation.
The timeline, which was seemingly produced by security investigators at Mandiant or based on data gathered by the firm, shows that the Lapsus$ group was able to use extremely well known and widely available hacking tools, like the password-grabbing tool Mimikatz, to rampage through Sitel's systems.
Mimikatz (Hacktool.Mimikatz): Tool designed to steal credentials
To laterally move within the target network, Mimikatz was used to dump passwords.
Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."
To facilitate privilege escalation, SHADOW-EARTH-053 has been found to use Mimikatz, while lateral movement is accomplished using a custom remote desktop protocol (RDP) launcher and C# implementation of SMBExec known as Sharp-SMBExec.
Impacket is further used to facilitate credential dumping through LSASS; the threat actor also leveraged the commodity credential theft tool Mimikatz in identified intrusions in 2025.
"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."
"It also uses two custom versions of Mimikatz..."
“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”
"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."
"...other tools including Mimikatz..."
"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."
“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”
"...using the credential harvesting tool Mimikatz."
"...using the credential harvesting tool Mimikatz."
Persistence is achieved by emplacement of ASPX webshells that allow execution of Mimikatz for credential recovery.
...use Mimikatz to harvest credentials...
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
The GreyEnergy group uses fairly standard tools for these tasks: Nmap and Mimikatz.
"Pypykatz (a Python version of Mimikatz)"
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
“The group continues to push various custom Mimikatz variants and keyloggers for credential harvesting purposes…”
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.
...a manual on deploying Cobalt Strike, mimikatz to dump NTLM hashes...
Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
Sandworm Team used UPX to pack a copy of Mimikatz.
Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.
Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...
Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.
We identified a different config.dat file being used for different purposes, like information gathering through Pyxie, Lazagne and Mimikatz...
...an operator repeatedly and infrequently revisited a compromised network whenever an Endpoint Detection and Response (EDR) tool detected or quarantined tools like HYPERBRO and Mimikatz.
"A modified mimikatz which extracts passwords from memory."
"...immediately executed a Zerologon exploit against the organization’s domain controller using the Mimikatz tool."
The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.
we also observed Mimikatz... uses the SEKURLSA::LogonPasswords module
One is “CreateMimi1Bat”; which likely executes Mimikatz (executes PowerShell scripts: ccd61.ps1 and Invoke-bypassuac), according to Arbor.
The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer
By abusing legitimate tools such as Cobalt Strike, Mimikatz, ProcDump, AdFind, and WinPEAS, the group conducts credential theft, privilege escalation, lateral movement, and data exfiltration.
The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.
Attackers also used Getpass, a custom Mimikatz DLL, masquerading as a Palo Alto tool, which automatically harvests credentials from 10 Windows authentication packages by accessing lsass.exe memory.
The Lazarus Group's Medusa ransomware campaign includes the use of various tools - RP_Proxy, a custom proxy utility Mimikatz, a publicly available credential dumping program Comebacker, a custom backdoor exclusively used by the threat actor InfoHook, an information stealer previously identified as used in conjunction with Comebacker BLINDINGCAN (aka AIRDRY or ZetaNile), a remote access trojan ChromeStealer, a tool for extracting stored passwords from the Chrome browser.
Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.
"UNC2596 leveraged credential theft tools such as Mimikatz and WICKER."
"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."
Microsoft Defender Antivirus detects threat components as ... HackTool:Win32/Mimikatz ... HackTool:Win64/Mimikatz
"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."
Additional Credential Theft... mimikatz.exe
“CHERNOVITE could drop additional tools, such as Mimikatz, to gather credentials…”
Exploited software
MITRE ATT&CK
Reporting
The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.