Skip to main content
Mallory
MalwareRansomwareUsed by 50 actors

Nishang

Nishang is a collection of PowerShell scripts and payloads used for offensive and post-exploitation activity on Windows systems. The provided content specifically references the Get-PassHashes script, which requires administrative privileges and was used to dump password hashes, and the Invoke-PowerShellTCPOneLine utility, a PowerShell-based reverse shell that initiates a callback to a remote command-and-control server. Detection content notes command-line indicators such as Net.Sockets.TCPClient and System.Text.ASCIIEncoding in PowerShell executions, consistent with remote control or data exfiltration behavior. Nishang activity is mapped to MITRE ATT&CK T1059.001 (PowerShell). In the supplied incident reporting, Nishang was used during a Medusa ransomware intrusion for credential access via Get-PassHashes after attackers had gained access to vulnerable internet-facing infrastructure and conducted broader post-compromise activity including defense evasion, lateral movement, and ransomware deployment. High-confidence indicators from the content include use of Get-PassHashes for password hash dumping and Invoke-PowerShellTCPOneLine for reverse-shell C2 callbacks.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

50 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
hafnium

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
FIN10

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
TA2541

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
TeamTNT

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
BRONZE BUTLER

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
CopyKittens

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
LazyScripter

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
APT33

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Chimera

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
UNC3886

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Blue Mockingbird

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Poseidon Group

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Kimsuky

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
SideWinder

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
APT32

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
TA459

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Gallmaker

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Molerats

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
MoustachedBouncer

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
GALLIUM

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Stealth Falcon

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
TA505

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
ToddyCat

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Gorgon Group

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
APT41

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
FIN6

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
DarkHydrus

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
FIN13

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
APT28

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Gamaredon Group

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Lotus Blossom

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
HEXANE

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
OilRig

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Lazarus

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Silence

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
APT39

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
menuPass

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
APT3

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Dragonfly

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Winter Vivern

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Turla

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Tonto Team

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Sandworm

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
APT5

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Volt Typhoon

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
FIN8

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
FIN7

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Cobalt Group

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Leviathan

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
Threat Group-3390

The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.

via splunk researchresearch.splunk.com
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1059.001PowerShellEvidence2
TacticExecution

PowerShell was leveraged by the threat actor to conduct various malicious activity such as downloading executables, disabling Microsoft Defender, deleting executables, and conducting discovery activity.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution50

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.