Impacket is an open-source collection of Python libraries and command-line tools for interacting with Windows network protocols and services, extensively used for legitimate administration, penetration testing, and adversary post-exploitation. Its modules support SMB, RPC, WMI, LDAP, Kerberos, NTLM, and Active Directory operations. Threat actors frequently abuse Impacket for internal reconnaissance, remote service execution, NTLM relay, credential dumping, extraction of SAM and LSA secrets, and Active Directory replication attacks. It has been observed in intrusions attributed to state-linked actors including APT10 and in ransomware-related activity involving Black Basta, Qilin affiliates, Warlock/GOLD SALEM, and other criminal operators. Impacket is principally used against Windows and Active Directory environments, although standalone Linux builds can be run from compromised Linux systems or edge appliances to target internal Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The operator deployed a standalone Linux build of Impacket’s secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from internal Windows systems.
Post-exploitation : Impacket , attaques NTLM relay, mouvement latéral
A working proof-of-concept (PoC) exploit has been released for a new NTLM reflection bypass flaw that enables SYSTEM-level access on Windows Server 2025. The vulnerability, tracked as CVE-2026-24294, abuses a feature introduced in Windows 11 24H2 and Windows Server 2025 that allows SMB connections over arbitrary TCP ports.
Impacket is a versatile, dual-use tool that uses Python-based scripts to exploit legitimate Windows services and protocols... threat actors frequently use psexec.py, smbexec.py, and wmiexec.py scripts within Impacket to execute code remotely on Windows systems without additional payloads or tools.
52 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UAT-11988 deployed open-source tools including Impacket, Invoke-TheHash, and AV killers before deploying Qilin ransomware.
User credentials are gained through a variety of different means including exploitation of public-facing appliances, insecurely stored credentials, extracting the Active Directory database file (NTDS.dit), enumerating existing stored sessions, credential dumping through LSASS, and use of the Mimikatz and Impacket tools
APT10 exploited a vulnerability in the web interface of a security tool, planted a version of the ASPXCSharp web shell, and then used a tool called Impacket to scan a target company's internal network.
Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.
Microsoft also observed the use of PsExec and Impacket for lateral movement and the use of Group Policy Objects (GPO) to deploy the Warlock payload.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
“The SYSTEM-level RCE… was already equivalent to domain admin, and the agent simply used Impacket or native Windows binaries to add a rogue account to the Domain Admins group.” | The agent simply used Impacket or native Windows binaries to add a rogue account to the Domain Admins group.
“The SYSTEM-level RCE… was already equivalent to domain admin, and the agent simply used Impacket or native Windows binaries to add a rogue account to the Domain Admins group.” | The agent simply used Impacket or native Windows binaries to add a rogue account to the Domain Admins group.
The earliest evidence of compromise was a secretsdump from an unidentified endpoint of the targeted organization to one of the domain controllers.
Microsoft Defender reported "Behavior:Win32/RegDump.SA" ... Loading the file into regedit confirmed that we were dealing with a SAM hive... Impacket’s secretsdump.py uses exactly this naming pattern when remotely saving registry hives.
“Using Impacket, ADRecon, and ADVipscan, and the custom LDAP brute-forcing utility REALBREEZE to conduct internal reconnaissance.”
Python scripts ... ensure [tasks] have actually completed. These include tasks like administrator access, account verification, Active Directory collection, domain and network discovery.
Microsoft stated that the threat actors used Impacket tools to execute the malware.
Impacket performs the registry operation remotely through the Windows Remote Registry service using the MS-RRP protocol. It connects to the winreg RPC interface over SMB (\pipe\winreg).
It was followed by the execution of discovery commands using wmiexec in the context of the built-in domain administrator account.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
98 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A standalone Linux build of Impacket's secretsdump was deployed to compromised SonicWall SMA1000 appliances to dump SAM and LSA secrets, extract credentials, and support DCSync/pass-the-hash activity against internal Active Directory systems.
An open-source offensive networking framework deployed by UAT-11988 during post-compromise operations.
Mentioned only as an example string for query-language starts-with-any matching; no malicious use or specific activity is discussed.
Offensive post-exploitation toolkit used to interact with compromised systems and extract data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.