Pypykatz is a Python implementation of Mimikatz functionality used for credential dumping and credential harvesting on Windows systems. It is publicly available and is commonly employed as post-compromise tooling to extract credentials from compromised hosts, supporting follow-on privilege escalation, lateral movement, and broader network compromise.
The tool has been observed in intrusion activity by multiple threat actors, including STIBNITE and APT15-associated operations, as well as in ransomware intrusions where operators used it alongside frameworks such as Cobalt Strike and implants such as SystemBC. In these contexts, Pypykatz has been used to steal administrator credentials and facilitate movement to high-value systems including domain controllers and virtualization infrastructure.
Pypykatz is best characterized as a credential-theft utility rather than a standalone access malware family. Its operational role is typically post-exploitation credential collection after initial access has already been established through other means such as phishing, spoofed credential theft sites, malware infection, or exploitation. It targets Windows environments and is frequently used in enterprise intrusions where harvested credentials can enable persistence, privilege escalation, and lateral movement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers combine this with credential theft (Mimikatz/Pypykatz), lateral movement (Cobalt Strike, SystemBC), and backup destruction to maximize impact and enable double-extortion.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
STIBNITE uses an executable package of a Python-based implementation of Mimikatz (PypyKatz) and the open-source LaZagne credential collection project for credential harvesting.
"...used Cobalt Strike and Pypykatz (a Python version of Mimikatz) to steal the credentials..."
Mimikatz, Pypykatz, Safetykatz – Publicly available credential-dumping tools...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
STIBNITE uses an executable package of a Python-based implementation of Mimikatz (PypyKatz) and the open-source LaZagne credential collection project for credential harvesting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential dumping tool present in an archive (Evidencia.rar) associated with the investigated activity; likely used for credential extraction during post-exploitation.
Python implementation of Mimikatz-like credential extraction used by attackers to dump credentials and authentication material for escalation and movement.
Python implementation of Mimikatz used to extract credentials from memory to facilitate privilege escalation and lateral movement.
Python implementation/variant of Mimikatz-style credential dumping used to extract Windows secrets from memory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.