Dumpert is a credential-dumping tool focused on dumping LSASS memory on Windows systems. The content explicitly describes it as an LSASS dumping tool that uses direct Windows system calls and API unhooking, rather than standard ReadProcessMemory-based approaches, to evade user-mode hooks and some AV/EDR monitoring. It is referenced as a dual-use or pentesting-style utility alongside tools such as Mimikatz and ProcDump, and is associated with MITRE ATT&CK OS Credential Dumping: LSASS Memory (T1003.001).
Observed and described capabilities include dumping LSASS memory to obtain credentials and supporting stealthier execution through direct syscalls and API unhooking. The content notes it has been used or referenced in intrusion activity involving credential theft, including uploads of Dumpert during post-compromise operations after exploitation of Microsoft SharePoint CVE-2019-0604 against Middle East government organizations in 2019, where actors also used webshells, Mimikatz, and Impacket tooling for discovery and lateral movement. In that reporting, Dumpert was uploaded as dmp.exe and attributed to Outflanknl’s GitHub repository. The content also states Chimera leveraged direct Windows system calls via Dumpert, and a 2024 joint advisory on DPRK Andariel/Onyx Sleet reports the actors used credential theft tools such as Mimikatz, Dumpert, and ProcDump.
Targeting reflected in the supporting content includes Windows enterprise environments, especially where attackers seek credential access from LSASS, with victim sectors and organizations mentioned in related incidents including Taiwan government agencies, Middle East government organizations, and defense, aerospace, nuclear, engineering, medical, and energy organizations in reporting on actor tradecraft. High-confidence indicators directly mentioned in the content are limited; one explicit observed filename is dmp.exe in the SharePoint intrusion reporting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Chimera added extracted key code snippets from both Mimikatz and Dumpert to their customized Skeleton Key.
The actors employ... credential theft utilities and dual-use tools such as Mimikatz, Dumpert, and ProcDump...
4 distinct techniques documented for this family, organized by ATT&CK tactic.
"Process Injection is a versatile technique that adversaries leverage to perform a wide range of malicious activity... code can inherit the privilege level of the process it’s injected into... allows payloads to be launched within the memory space of a running process without needing to drop any malicious code to disk."
"Process Injection is a versatile technique that adversaries leverage to perform a wide range of malicious activity... code can inherit the privilege level of the process it’s injected into... allows payloads to be launched within the memory space of a running process without needing to drop any malicious code to disk."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used to dump LSASS process memory to obtain credentials; often used alongside injection/evasion tradecraft to access protected processes.
Dumpert is referenced as a source of code snippets incorporated into a customized Skeleton Key used by APT Chimera to bypass API monitoring and support credential-access-related operations.
LSASS memory dumping tool that uses direct system calls and API unhooking to evade user-mode security hooks while obtaining credential material from LSASS.
LSASS dumping tool (direct syscalls + API unhooking for evasion) uploaded to a related webshell to dump credentials; noted as relatively new at the time and not previously observed by the authors in CVE-2019-0604 exploitation incidents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.