John the Ripper is a password-cracking tool referenced in the content as being used to crack password hashes obtained during credential access activity. The content specifically notes the unshadow utility as part of John the Ripper, and cites John the Ripper alongside Hashcat as a hash-cracking tool adversaries may use after dumping credentials or obtaining hashes from sources such as SAM, NTDS.dit, or similar credential stores. Its role in the described tradecraft is offline password cracking using recovered hashes, including attempts to derive plaintext passwords after credential dumping. No specific threat actor, malware family association, infection vector, targeted industry, or concrete indicators of compromise are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-24974 - Unauthorized access to the "\\openvpn\\service" named pipe in Windows, allowing an attacker to remotely interact with it and launch operations on it
CVE-2024-1305 - A memory overflow vulnerability leading to DoS in Windows
CVE-2024-27903 - A vulnerability in the plugin mechanism leading to RCE in Windows, and LPE and data manipulation in Android, iOS, macOS, and BSD
CVE-2024-27459 - A stack overflow vulnerability leading to a Denial-of-service (DoS) and LPE in Windows
7 distinct techniques documented for this family, organized by ATT&CK tactic.
I checked the hashes with John the Ripper using the NT, as400-des, and as400-ssha1 formats, and everything worked as expected. The program can crack the password based on the recovered hashes.
“I copied the contents of hashdump.txt locally and ran John the Ripper against it, specifying the NT hash format.”
but the id_rsa is password protected, here we use john the ripper for getting the password. by cracking the password we get the credentials for the second user, the password is beeswax
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offline password cracking tool used to recover plaintext passwords from dumped hashes (e.g., from /etc/shadow).
Offline password hash cracking tool used after credential dumping to recover plaintext passwords from captured hashes.
Password cracking suite; referenced via its 'unshadow' utility to combine /etc/passwd and /etc/shadow for offline cracking/credential access workflows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.