Mimikatz is a widely used Windows post-exploitation tool focused on credential access. It is best known for extracting plaintext credentials, password hashes, Kerberos tickets, and other authentication material from LSASS memory and related Windows security subsystems. It is routinely used by both red teams and malicious operators after initial compromise to obtain privileged credentials, expand access, and support follow-on actions such as lateral movement, persistence, and broader domain compromise.
The tool is frequently deployed in hands-on intrusions by ransomware operators, espionage actors, and initial access brokers. Reported use spans campaigns associated with groups such as Turla, Hyadina, and operators leveraging Citrix appliance compromises before moving into Windows environments. It commonly appears alongside administrative and dual-use tooling such as PsExec, remote access software, password recovery utilities, and network scanners, reflecting its role in post-compromise credential harvesting rather than initial delivery.
Mimikatz primarily targets Windows systems and is commonly used to dump LSASS memory, recover cached credentials, and extract Kerberos tickets for reuse. Its output can enable privilege escalation, lateral movement, and access to network shares or additional hosts. Defenders often monitor for anomalous LSASS access, memory dumping behavior, and execution from unusual directories because the tool remains a standard component of many intrusion playbooks despite broad detection coverage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
16 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Уязвимость RoguePlanet, ранее обнаруженная ИБ-исследователем Nightmare Eclipse, получила идентификатор CVE-2026-50656 (7,8 балла по шкале CVSS). Напомним, что проблема связана с возникновением состояния гонки в Microsoft Defender и позволяет повысить привилегии до уровня SYSTEM и выполнить произвольный код на полностью обновленных системах под управлением Windows 10 и Windows 11.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks. Microsoft has issued security advisories acknowledging the exploitation potential of this CVE.
Latest commit gentilkiwi [new] mimikatz lsadump::postzerologon, to reinit DC password both in …
Kaspersky researchers revealed ... the attackers exploit Internet-exposed Fortigate SSL VPN servers unpatched against the CVE-2018-13379 vulnerability ... The FBI and CISA warned ... APT actors scanning for Fortinet SSL VPN appliances vulnerable to CVE-2018-13379 exploits ... Fortinet also warned customers to patch their appliances against the CVE-2018-13379 ... "CVE-2018-13379 is an old vulnerability resolved in May 2019"
Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. In December 2025, Fortinet disclosed this improper verification of cryptographic signature vulnerability that facilitates an SSO login bypass on affected appliances.
Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA) ... malicious activity ... consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems exposed to the internet. CVE-2025-32975 (CVSS score: 10.0) refers to an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065
"...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..." | Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 ... Security firm Volexity spotted hackers targeting Exchange servers on Jan. 3, when it saw CVE-2021-26855 being exploited.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Attackers combine this with credential theft (Mimikatz/Pypykatz), lateral movement (Cobalt Strike, SystemBC), and backup destruction to maximize impact and enable double-extortion.
This analytic story covers attacks exploiting CVE-2024-4577, a remote code execution (RCE) vulnerability in the PHP-CGI implementation on Windows. Attackers leverage this vulnerability to gain initial access, deploy Cobalt Strike using the "TaoWu" kit for post-exploitation activities, and establish persistence.
Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. This vulnerability allows for remote code execution on the ManageEngine application.
"...a threat actor exploited the CVE-2022-40684 vulnerability to bypass authentication on the organization’s Fortinet VPN and gain initial access. Using various Windows tools and services, including smbexec.py from the Impacket toolkit, the attacker executed commands and moved laterally across the network."
60 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The remaining tool, Mimikatz, is widely known for extracting credentials and authentication material from Windows systems and is frequently abused during post-compromise activity.
Turla operators also use publicly available tools such as Mimikatz and Metasploit when they help the intrusion blend into normal administrative activity.
During post-exploitation, the operators used Metasploit to facilitate movement across Windows systems and Mimikatz for LSASS credential dumping, enabling access to higher-privileged accounts on the control plane of the transport network.
While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
While they frequently use common open-source tools such as SoftEther VPN, Mimikatz, and VNT, they have recently introduced TinyRCT, a bespoke, previously undocumented backdoor.
Subsequently, the attacker used Mimikatz to dump credential information (LSASS Memory, T1003.001).
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Once inside a network, Qilin escalates privileges by exploiting vulnerabilities or using legitimate tools like Mimikatz, PsExec or Powershell
The remaining tool, Mimikatz, is widely known for extracting credentials and authentication material from Windows systems and is frequently abused during post-compromise activity.
Дамп LSASS (T1003.001) через Mimikatz или LaZagne, эксплуатация уязвимостей Active Directory, Kerberoasting.
A recent Qilin ransomware intrusion has revealed a stealthy privilege escalation technique that abuses Active Directory’s built-in replication protocols to harvest domain credentials, including the coveted KRBTGT hash and NTLM password hashes for every account in the domain. | This combination is the signature of DCSync, a technique popularized by tools like Mimikatz that impersonates a domain controller to request password data via the Directory Replication Service Remote Protocol (MS-DRSR), without ever touching disk on a DC.
Investigators observed fourteen open-source tools designed to recover credentials from web browsers, email clients and instant messaging applications, as well as utilities capable of extracting Wi-Fi credentials.
Next, Hyadina took it up another notch by deploying a toolkit made of 14 different tools... used for different kinds of Windows-based credential theft: browser, email, and instant messenger stealers; Wi‑Fi and live network traffic interceptors; and more.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A credential-dumping and authentication theft tool abused by the attackers during post-compromise activity to extract credentials from Windows systems.
Credential dumping tool used to access LSASS and steal credentials during privilege escalation.
Tool associated with credential dumping via LSASS memory access; mentioned as an example of malware/tooling patterns detectable through Sysmon ProcessAccess events.
A credential dumping tool used here to dump LSASS memory and extract credential material including cached credentials and Kerberos tickets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.