Skip to content

Mimikatz

Mimikatz is a widely used Windows post-exploitation tool focused on credential access and abuse of Windows authentication mechanisms.

Profile source: Mallory opens in a new tab

Mimikatz

Family profile

Mimikatz is a widely used Windows post-exploitation tool focused on credential access and abuse of Windows authentication mechanisms. Originally developed by Benjamin Delpy, it is best known for extracting credentials from LSASS memory, recovering plaintext passwords, NTLM hashes, Kerberos tickets, and other authentication material from compromised hosts. It is also commonly used to perform Active Directory replication abuse through its DCSync functionality, allowing operators with sufficient replication privileges to remotely obtain account secrets from domain controllers without directly dumping the NTDS database.

The tool is routinely deployed after initial compromise by a broad range of threat actors, including ransomware operators and state-linked intrusion sets, as part of hands-on-keyboard operations in Windows enterprise environments. Reported use cases include credential dumping from host memory, harvesting cleartext credentials when WDigest or malicious SSP-based logging is enabled, and supporting privilege escalation and lateral movement by enabling follow-on techniques such as pass-the-hash, Kerberos abuse, and domain-wide credential theft. Mimikatz has also been used alongside other post-exploitation tooling for reconnaissance, tunneling, remote administration, and ransomware staging.

Mimikatz targets Windows systems and is especially relevant in domain environments because of its ability to access local credentials and abuse domain replication rights. Its modules and derivatives have made it a standard component of many intrusion playbooks, and its behavior is frequently referenced in detection engineering for credential dumping and related post-compromise activity.

Capabilities

  • Credential Theft
  • Lateral Movement
  • Post Exploitation
  • Privilege Escalation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 6, 2026
Feed role
C2 / Distribution
Host form
12 IP / 7 hostnames

Leading locations

  • CN3
  • KR3
  • NL3
  • US3
  • LU2
  • DE1
  • DK1
  • HK1
  • JP1
  • RU1

Leading providers

  • Ghosty Networks LLC2
  • Omegatech LTD2
  • Shenzhen Tencent Computer Systems Company Limited2
  • SK Broadband Co Ltd2
  • Amazon.com, Inc.1
  • CTG Server Limited1

Infrastructure traits

  • Hosting 12
  • Anycast 1
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

103 named in public reporting
Toy Ghouls

Installation d’outils post-compromission : OpenSSH, socks5.exe, SoftPerfect Network Scanner, Mimikatz

Larva-26009

Additionally, Mimikatz, the Fscan scanner, the gost proxy, and the user account creation tool can be used as plugins.

Qilin

Mimikatz — dump de credentials en mémoire

Hyadina

The remaining tool, Mimikatz, is widely known for extracting credentials and authentication material from Windows systems and is frequently abused during post-compromise activity.

Turla

Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.

Red Menshen

During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.

CL-STA-1062

While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.

UAT-7237

While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.

DragonForce

Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001).

FIN7

FIN7 and Carbanak abused ProcDump to dump LSASS memory ▸ PowerShell Mimikatz scripts also widely used

Carbanak

FIN7 and Carbanak abused ProcDump to dump LSASS memory ▸ PowerShell Mimikatz scripts also widely used

Makop

Along with the classical abuse of Microsoft SysInternal tools such as PsExec and other well-known open-source tools such as Putty and the never-missing Mimikatz, during recent operations, Makop abused even more peculiar software.

APT Chimera

A customized modification of the original Mimikatz, Mimikat.dll was designed to specifically inject the Skeleton Key to allow the attackers persistent, unfettered Lateral Movement across the network.

Scattered Spider

Additional tradecraft and techniques: Using open-source tooling: Mimikatz, Hekatomb, Lazagne, gosecretsdump, smbpasswd.py, LinPEAS, ADFSDump.

menuPass

In this campaign, the attackers are also seen dumping credentials, including by using a custom Mimikatz loader. This version of Mimikatz drops mimilib.dll to obtain credentials in plain text for any user that is accessing the compromised host and provides persistence across reboots.

Twelve

The adversary used mimikatz to obtain user credentials. They saved the utility file under the name calculator.exe to disguise its real purpose.

GALLIUM

For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.

Storm-2603

Microsoft’s profile of the group noted the execution of Mimikatz “specifically targeting the Local Security Authority Subsystem Service (LSASS) memory to extract plaintext credentials.”

Head Mare

The investigation identified tools for obtaining credentials. Besides the publicly available mimikatz utility, the attackers used secretsdump and ProcDump.

APT41

The attackers also used Mimikatz to dump account credentials. Like the Pillager stealer, Mimikatz was rewritten and compiled into a DLL.

Threat Group-3390

For the pass-the-hash attacks, they used a custom modified version of Mimikatz, implemented in an executable named bK2o.exe. Due to the previously discussed overlaps between bK2o.exe (used in Operation Digital Eye), wsx.exe, wsx1.exe, mim221 components (used in Operation Tainted Love), and simplify_32.exe (used in Operation Soft Cell), we collectively refer to this collection of tools as mimCN.

Crypt Ghouls

We detected the use of the Mimikatz utility in some of the investigated attacks.

APT28

The toolkit was unchanged: X-Agent for keylogging and screenshotting, X-Tunnel for exfiltration, Mimikatz for credential theft.

Cobalt Group

Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.

BRONZE BUTLER

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

PittyTiger

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Blue Mockingbird

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Chimera

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Handala

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

TA505

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Kimsuky

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Whitefly

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

APT32

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

DarkHydrus

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

APT38

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

FIN6

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Cleaver

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

FIN13

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Lotus Blossom

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

OilRig

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

HEXANE

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Dragonfly

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

APT39

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

TEMP.Veles

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Leafminer

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Ke3chang

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Magic Hound

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

Lizar

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

MuddyWater

The hackers used well known tools, including Meterpreter, Mimikatz, Lazagne, Invoke-Obfuscation, and more.

WIZARD SPIDER

Before that, however, antivirus on HSE endpoints detected both Cobalt Strike and Mimikatz being deployed on the so-called Patient Zero workstation.

LAPSUS$

The timeline, which was seemingly produced by security investigators at Mandiant or based on data gathered by the firm, shows that the Lapsus$ group was able to use extremely well known and widely available hacking tools, like the password-grabbing tool Mimikatz, to rampage through Sitel's systems.

APT33

Mimikatz (Hacktool.Mimikatz): Tool designed to steal credentials

Vanilla Tempest

To laterally move within the target network, Mimikatz was used to dump passwords.

Earth Longzhi

Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."

Shadow-Earth-053

To facilitate privilege escalation, SHADOW-EARTH-053 has been found to use Mimikatz, while lateral movement is accomplished using a custom remote desktop protocol (RDP) launcher and C# implementation of SMBExec known as Sharp-SMBExec.

Storm-1175

Impacket is further used to facilitate credential dumping through LSASS; the threat actor also leveraged the commodity credential theft tool Mimikatz in identified intrusions in 2025.

UNC2447

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

SVR

“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”

slow#tempest

"...targeting Chinese-speaking users with Cobalt Strike and Mimikatz payloads."

Yanluowang

"...offensive security tools such as Cobalt Strike, PowerSploit, Mimikatz, and Impacket..."

APT29

“…executables that are likely to be detected (i.e. Mimikatz) were executed in memory…”

UNC2717

"...using the credential harvesting tool Mimikatz."

APT5

"...using the credential harvesting tool Mimikatz."

Warlock

Persistence is achieved by emplacement of ASPX webshells that allow execution of Mimikatz for credential recovery.

REF3927

...use Mimikatz to harvest credentials...

Mikroceen

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

GreyEnergy

The GreyEnergy group uses fairly standard tools for these tasks: Nmap and Mimikatz.

Calypso

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

Tonto

“The group continues to push various custom Mimikatz variants and keyloggers for credential harvesting purposes…”

ViciousPanda

"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."

CozyCar

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Andariel

The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.

Conti

...a manual on deploying Cobalt Strike, mimikatz to dump NTLM hashes...

Earth Lusca

Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).

FIN8

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Sandworm

Sandworm Team used UPX to pack a copy of Mimikatz.

Silence

Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.

APT1

Sandworm Team used Mimikatz to capture and use legitimate credentials... Emotet has been observed dropping password grabber modules including Mimikatz... NotPetya contains a modified version of Mimikatz to help gather credentials...

Agrius

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.

Gold Dupont

We identified a different config.dat file being used for different purposes, like information gathering through Pyxie, Lazagne and Mimikatz...

unc215

...an operator repeatedly and infrequently revisited a compromised network whenever an Endpoint Detection and Response (EDR) tool detected or quarantined tools like HYPERBRO and Mimikatz.

APT6

"A modified mimikatz which extracts passwords from memory."

TAC5279

"...immediately executed a Zerologon exploit against the organization’s domain controller using the Mimikatz tool."

Stonefly/Clasiopa

The actors then employ... privilege escalation using common credential stealing tools such as Mimikatz.

REF9019

we also observed Mimikatz... uses the SEKURLSA::LogonPasswords module

Greenbug

One is “CreateMimi1Bat”; which likely executes Mimikatz (executes PowerShell scripts: ccd61.ps1 and Invoke-bypassuac), according to Arbor.

Storm-0501

The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer

Mustang Panda

The analytic detects a user account initiating an Active Directory replication request, indicative of a DCSync attack... References https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer

Play

By abusing legitimate tools such as Cobalt Strike, Mimikatz, ProcDump, AdFind, and WinPEAS, the group conducts credential theft, privilege escalation, lateral movement, and data exfiltration.

Flax Typhoon

The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.

CL-STA-1087

Attackers also used Getpass, a custom Mimikatz DLL, masquerading as a Palo Alto tool, which automatically harvests credentials from 10 Windows authentication packages by accessing lsass.exe memory.

Lazarus

The Lazarus Group's Medusa ransomware campaign includes the use of various tools - RP_Proxy, a custom proxy utility Mimikatz, a publicly available credential dumping program Comebacker, a custom backdoor exclusively used by the threat actor InfoHook, an information stealer previously identified as used in conjunction with Comebacker BLINDINGCAN (aka AIRDRY or ZetaNile), a remote access trojan ChromeStealer, a tool for extracting stored passwords from the Chrome browser.

CL-UNK-1068

Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.

RomCom

"UNC2596 leveraged credential theft tools such as Mimikatz and WICKER."

UNC1945

"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."

Contagious Interview

Microsoft Defender Antivirus detects threat components as ... HackTool:Win32/Mimikatz ... HackTool:Win64/Mimikatz

TraderTraitor

"Details of a recent Ryuk incident show a 15-step procedure for victim compromise, 2 of which include the use of the credential harvesting tools Mimikatz and LaZagne."

Chernovite

“CHERNOVITE could drop additional tools, such as Mimikatz, to gather credentials…”

Exploited software

Vulnerabilities linked to Mimikatz

16 CVEs

MITRE ATT&CK

Mimikatz in ATT&CK

77 distinct techniques

Techniques

77 techniques
T1059.001 PowerShell T1550.002 Pass the Hash T1078 Valid Accounts T1003.001 LSASS Memory T1649 Steal or Forge Authentication Certificates T1003.002 Security Account Manager T1003 OS Credential Dumping T1570 Lateral Tool Transfer T1027 Obfuscated Files or Information T1112 Modify Registry T1068 Exploitation for Privilege Escalation T1021.001 Remote Desktop Protocol T1555 Credentials from Password Stores T1003.006 DCSync T1562 Impair Defenses T1489 Service Stop T1105 Ingress Tool Transfer T1021 Remote Services T1059 Command and Scripting Interpreter T1565.001 Stored Data Manipulation T1134 Access Token Manipulation T1036 Masquerading T1562.001 Disable or Modify Tools T1059.005 Visual Basic T1620 Reflective Code Loading T1055 Process Injection T1070.004 File Deletion T1550.003 Pass the Ticket T1556.001 Domain Controller Authentication T1550 Use Alternate Authentication Material T1074.001 Local Data Staging T1070 Indicator Removal T1003.003 NTDS T1574.001 DLL T1078.002 Domain Accounts T1003.004 LSA Secrets T1484.001 Group Policy Modification T1548 Abuse Elevation Control Mechanism T1558.001 Golden Ticket T1558 Steal or Forge Kerberos Tickets T1134.001 Token Impersonation/Theft T1140 Deobfuscate/Decode Files or Information T1497 Virtualization/Sandbox Evasion T1558.003 Kerberoasting T1027.010 Command Obfuscation T1547 Boot or Logon Autostart Execution T1190 Exploit Public-Facing Application T1558.002 Silver Ticket T1556 Modify Authentication Process T1552.001 Credentials In Files T1222 File and Directory Permissions Modification T1608.002 Upload Tool T1083 File and Directory Discovery T1553.002 Code Signing T1569.002 Service Execution T1210 Exploitation of Remote Services T1059.003 Windows Command Shell T1204.002 Malicious File T1588.002 Tool T1005 Data from Local System T1555.004 Windows Credential Manager T1555.003 Credentials from Web Browsers T1059.007 JavaScript T1047 Windows Management Instrumentation T1212 Exploitation for Credential Access T1218.013 Mavinject T1021.002 SMB/Windows Admin Shares T1036.005 Match Legitimate Resource Name or Location T1055.001 Dynamic-link Library Injection T1547.005 Security Support Provider T1129 Shared Modules T1218 System Binary Proxy Execution T1014 Rootkit T1543.003 Windows Service T1558.004 AS-REP Roasting T1003.005 Cached Domain Credentials T1211 Exploitation for Defense Evasion

Reporting

Research mentioning Mimikatz

Aug 3
Malware News

Cyber Conflict Briefing Q2 2026 - Malware Analysis - Malware Analysis, News and Indicators

The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

Aug 3
Cyberveille

Tendances ransomware - Semaine 31/2026 | CyberVeille

Aug 3
Hookphish

Ransomware Group qilin Hits: Service Electric

Aug 3
Hookphish

Ransomware Group qilin Hits: Freedom Claims Management

Aug 2
Hookphish

Ransomware Group shinyhunters Hits: Questel SAS

Aug 2
Hookphish

Ransomware Group qilin Hits: Wire Products

Aug 1
Cyberveille

Vague d'exploitation VPN : Palo Alto, Fortinet, Citrix et Check Point ciblés par des ransomwares | CyberVeille

Aug 1
Hookphish

Ransomware Group qilin Hits: Schreiner Trockenbau GmbH

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.