Mimikatz is a Windows post-exploitation credential-access tool widely used by penetration testers and cybercriminal threat actors. It can extract plaintext passwords, password hashes, and Kerberos tickets from Windows authentication memory, including LSASS, and can dump credentials from Security Account Manager and Local Security Authority secret stores. Ransomware affiliates and other financially motivated intruders frequently use Mimikatz after obtaining network access to harvest credentials that enable privilege escalation and lateral movement. It has been observed in operations associated with LockBit, Conti, Medusa, Warlock, Bad Rabbit, and other ransomware activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Nearly all tools leveraged are being used in their PowerShell versions, including Mimikatz and PowerSploit... Mimikatz, UAC Bypass, and Zerologon are a privilege escalation holy trinity...
The exploitation of ProxyShell in these attacks involves three vulnerabilities: CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 — the first two were patched in July 2021, while the latter was fixed in May 2021. | Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
shortly afterwards, credential-dumping tool Mimikatz was used to dump credentials from the system.
shortly afterwards, credential-dumping tool Mimikatz was used to dump credentials from the system.
Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
The fileless attack was delivered via Microsoft Word documents that exploited a former zero-day vulnerability in Word, CVE-2017-0199, to install a fileless attack variant of the Helminth Trojan agent. Microsoft released the patch for the vulnerability on April 11, but many organizations have not yet deployed the update.
Дамп LSASS ... через Mimikatz или LaZagne
Уязвимость RoguePlanet, ранее обнаруженная ИБ-исследователем Nightmare Eclipse, получила идентификатор CVE-2026-50656 (7,8 балла по шкале CVSS). Напомним, что проблема связана с возникновением состояния гонки в Microsoft Defender и позволяет повысить привилегии до уровня SYSTEM и выполнить произвольный код на полностью обновленных системах под управлением Windows 10 и Windows 11.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks. Microsoft has issued security advisories acknowledging the exploitation potential of this CVE.
Kaspersky researchers revealed ... the attackers exploit Internet-exposed Fortigate SSL VPN servers unpatched against the CVE-2018-13379 vulnerability ... The FBI and CISA warned ... APT actors scanning for Fortinet SSL VPN appliances vulnerable to CVE-2018-13379 exploits ... Fortinet also warned customers to patch their appliances against the CVE-2018-13379 ... "CVE-2018-13379 is an old vulnerability resolved in May 2019"
Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. In December 2025, Fortinet disclosed this improper verification of cryptographic signature vulnerability that facilitates an SSO login bypass on affected appliances.
Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA) ... malicious activity ... consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems exposed to the internet. CVE-2025-32975 (CVSS score: 10.0) refers to an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Attackers combine this with credential theft (Mimikatz/Pypykatz), lateral movement (Cobalt Strike, SystemBC), and backup destruction to maximize impact and enable double-extortion.
This analytic story covers attacks exploiting CVE-2024-4577, a remote code execution (RCE) vulnerability in the PHP-CGI implementation on Windows. Attackers leverage this vulnerability to gain initial access, deploy Cobalt Strike using the "TaoWu" kit for post-exploitation activities, and establish persistence.
Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. This vulnerability allows for remote code execution on the ManageEngine application.
"...a threat actor exploited the CVE-2022-40684 vulnerability to bypass authentication on the organization’s Fortinet VPN and gain initial access. Using various Windows tools and services, including smbexec.py from the Impacket toolkit, the attacker executed commands and moved laterally across the network."
50 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The following TTPs and IOCs have been published by multiple researchers ... TA0006 - Credential Access Mimikatz.
The group is using AnyDesk or SimpleHelp, Advanced IP Scanner for reconnaissance, and Mimikatz to dump credentials from the LSASS process.
Previous research indicates that the threat actors employed Mimikatz and registry hive dumping.
User credentials are gained through a variety of different means including exploitation of public-facing appliances, insecurely stored credentials, extracting the Active Directory database file (NTDS.dit), enumerating existing stored sessions, credential dumping through LSASS, and use of the Mimikatz and Impacket tools
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
BRONZE BUTLER ... Tools ... ABK, BBK, Casper, Daserf, Datper, DGet, down_new, Ghostdown, Gofarer, gsecdump, Mimikatz, MSGet, Netboy, RarStar, Screen Capture Tool, ShadowPad, ShadowPy, T-SMB
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Mimikatz, UAC Bypass, and Zerologon are a privilege escalation holy trinity with some help of NTDS dumps.
“many of their attacks utilize known security tools such as Mimikatz and LaZagne.”
"Instead, let’s dump LSASS locally and see what’s there in the results: ... Invoke-Mimikatz -DumpCreds."
T1003.002 Security Account Manager ... Mimikatz (lsadump:sam and secrets modules) - modules to dump creds from the SAM and LSA registry keys.
Mimikatz, UAC Bypass, and Zerologon are a privilege escalation holy trinity with some help of NTDS dumps.
T1003.004 LSA Secrets ... LSASecretsdumper - LSA secrets stealing with LsaOpenSecret and LsaQuerySecret APIs.
T1003.005 Cached Domain Credentials ... Mimikatz (lsadump::sam, cache, lsa, and secrets submodules).
debug.exe was used to impersonate a Domain Controller and retrieve user credentials from another DC via MS-DRSR.
Researchers have made improvements on exploit code, such as removing the requirement to reset passwords during exploitation... threat actors can... change computer passwords in Active Directory (AD).
Tests confirmed the successful deletion of example protected binaries such as WdFilter.sys , MsMpEng.exe and WdNisDrv.sys during boot. Since the MsMpEng.exe service binary is removed significantly before the Service Control Manager even attempts to launch it, the security solution fails to start entirely.
125 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-dumping tool used to harvest credentials, including from the LSASS process.
Credential-dumping tool used by Storm-1175 to extract credentials from the LSASS process following compromise.
Credential-access tool reportedly used by the operators in earlier activity, alongside registry-hive dumping and DCSync techniques.
Credential-dumping tool used to extract plaintext credentials from memory on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.