pypykatz is a publicly available, Python-based implementation of Mimikatz used for credential dumping and harvesting in Windows environments. It is a dual-use security tool rather than a distinct malware family. Threat actors deploy it after compromise to obtain credentials, including those of privileged domain accounts, that can support subsequent lateral movement and access to additional systems. It has also been deployed as a packaged executable.
Observed users include Storm-0506, Storm-2570, STIBNITE, and APT15. Storm-0506 used pypykatz alongside Cobalt Strike to steal two domain administrators’ credentials during an intrusion against a North American engineering firm that culminated in Black Basta ransomware deployment. Storm-2570 uses it within ransomware-related credential-harvesting operations. STIBNITE used it in campaigns targeting government and wind-generation entities in Azerbaijan, while APT15 used it in a campaign targeting foreign affairs ministries in Central and South America. These uses establish its role as a post-compromise credential-access tool, not as an initial-access mechanism or ransomware payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers combine this with credential theft (Mimikatz/Pypykatz), lateral movement (Cobalt Strike, SystemBC), and backup destruction to maximize impact and enable double-extortion.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor then used Cobalt Strike and Pypykatz (a Python version of Mimikatz) to steal the credentials of two domain administrators.
For credential access and harvesting, Storm-2570 uses tools like Mimikatz, LaZagne, and pypykatz.
STIBNITE uses an executable package of a Python-based implementation of Mimikatz (PypyKatz) and the open-source LaZagne credential collection project for credential harvesting.
Mimikatz, Pypykatz, Safetykatz – Publicly available credential-dumping tools...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
For credential access and harvesting, Storm-2570 uses tools like Mimikatz, LaZagne, and pypykatz.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-access and credential-harvesting tool used by Storm-2570.
Credential dumping tool present in an archive (Evidencia.rar) associated with the investigated activity; likely used for credential extraction during post-exploitation.
Python implementation of Mimikatz-like credential extraction used by attackers to dump credentials and authentication material for escalation and movement.
Python implementation of Mimikatz used to extract credentials from memory to facilitate privilege escalation and lateral movement.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.