Skip to content

MimiKatz

Varonis summarizes Mimikatz as an open-source application that allows users to view and save authentication credentials like Kerberos tickets. Benjamin Delpy continues to lead Mimikatz developments, so the toolset works with the current release of Windows and includes the most up-to-date attacks.

Attackers commonly use Mimikatz to steal credentials and escalate privileges: in most cases, endpoint protection software and anti-virus systems will detect and delete it. Conversely, pentesters use Mimikatz to detect and exploit vulnerabilities in your networks so you can fix them.

Linked Threat Actors

APT10APT32AnunakGALLIUM

C2 Infrastructure

Hosting/VPS 100%

Last 7 days

Jun 12, 2026
C2 Hosts: 1

Further Reading

Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S. opens in a new tab

Although heavily focused on the Middle East, Elfin (aka APT33) has also targeted a range of organizations in the U.S. including a number of major corporations.

symantec-blogs.broadcom.com
CUBA Ransomware Campaign Analysis — Elastic Security Labs opens in a new tab

Elastic Security observed a ransomware and extortion campaign leveraging a combination of offensive security tools, LOLBAS, and exploits to deliver the CUBA ransomware malware.

elastic.co
Ransomware Spotlight: RansomEXX | Trend Micro (US) opens in a new tab

RansomEXX is a ransomware variant that gained notoriety after a spate of attacks in 2020 and continues to be active today. With its targeted nature and history for choosing high-profile victims, we...

trendmicro.com
Exchange servers under siege from at least 10 APT groups opens in a new tab

ESET Research shows that at least 10 APT groups are exploiting the recent Microsoft Exchange vulnerabilities to compromise email servers across the world.

welivesecurity.com
Worok: The big picture opens in a new tab

ESET Research has uncovered Worok, a new cyberespionage group that targets high-profile organizations based in Asia and operating in various sectors.

welivesecurity.com
Chinese Hackers Have Pillaged Taiwan's Semiconductor Industry opens in a new tab

A campaign called Operation Skeleton Key has stolen source code, software development kits, chip designs, and more.

wired.com
He Perfected a Password-Hacking Tool—Then the Russians Came Calling opens in a new tab

How a program called Mimikatz became one of the world's most widespread and powerful password stealers.

wired.com
FBI says an Iranian hacking group is attacking F5 networking devices opens in a new tab

Sources: Attacks linked to a hacker group known as Fox Kitten (or Parisite), considered Iran's "spear tip" when it comes to cyber-attacks.

zdnet.com
Il polo italiano della Cyber Security opens in a new tab

Costruiamo un digitale sicuro, insieme. Sicurezza, Resilienza, Innovazione Tinexta Cyber è una delle principali realtà italiane nel campo della cybersecurity e della system integration, parte del G...

yoroi.company