Responder is an open-source adversary-in-the-middle tool used to poison Link-Local Multicast Name Resolution (LLMNR), NetBIOS Name Service (NBT-NS), and multicast DNS (mDNS) requests on local networks. By responding to name-resolution queries and related proxy-discovery traffic, it can cause systems to attempt authentication to attacker-controlled services, enabling capture of NTLM authentication material and, in some configurations, credentials. It is also used to abuse Web Proxy Auto-Discovery Protocol (WPAD) behavior for NTLM credential capture. Responder is widely used in penetration testing and has been abused by threat actors including APT28 and Lazarus Group for credential access and internal-network operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These behaviors indicate that the server may have installed an LLMNR poisoning tool, such as Responder.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Credential Access T1557.001 — Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning ntlmrelayx, Responder.”
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
...using a mix of custom and public tools such as Microsocks, FRP, FScan, and Responder...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
"Which stored procedure triggered the outbound filesystem access? xp_dirtree" and "Which protocol carries the authentication attempt to the UNC path? SMB."
Атакующий, находящийся в той же сети, может подделать ответ и выдать себя за искомый хост, заставив жертву отправить свои учетные данные (а точнее, хэш пароля) ему.
“ntlmrelayx, Responder. NTLM coercion: nxc smb hostx.txt -M coerce_plus.”
«-D поднимает SOCKS5-прокси. Браузер и proxychains через него работают, но Responder, ARP-спуфинг, ICMP-сканирование — нет».
Атакующий, находящийся в той же сети, может подделать ответ и выдать себя за искомый хост, заставив жертву отправить свои учетные данные (а точнее, хэш пароля) ему.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A network poisoning and credential-capture tool used for LLMNR/NBT-NS attacks and NTLM credential interception.
Credential harvesting tool used for LLMNR/NBT-NS/MDNS poisoning and capture of authentication material.
Responder is a tool for LLMNR, NBT-NS, and MDNS poisoning, capturing credentials and relaying them for lateral movement or privilege escalation.
Responder is referenced as an LLMNR poisoning tool likely used post-exploitation for internal reconnaissance and credential access activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.