GSecDump is a Windows credential-dumping utility used to extract authentication material from compromised systems. It is associated with OS credential dumping activity against multiple Windows credential stores and sources, including the Security Account Manager (SAM), LSA secrets, Active Directory data, and logon-session credential material. Its primary purpose is harvesting password hashes and related secrets that can be used for follow-on credential theft, privilege escalation, and lateral movement within enterprise environments.
The tool has been observed in intrusion activity linked to several threat actors, including Ke3chang, Threat Group-3390, and Earth Akhlut (also known as Tonto Team/Cactus Pete/Lone Range), and has also been referenced in historical espionage operations such as Night Dragon. In operational use, GSecDump commonly appears alongside other post-exploitation and credential-access tooling such as Mimikatz, LaZagne, and SecretsDump-class utilities.
GSecDump targets Windows systems and is relevant both on standalone hosts and in domain environments because it can obtain local password hashes and other credential material useful for expanding access. Its behavior aligns with credential-access tradecraft centered on dumping SAM contents and LSA secrets, making it a common subject of defensive detections for ATT&CK T1003-related activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
GSecDump is a popular credential dumper that is used to obtain password hashes and LSA secrets from Windows machines.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool referenced as part of Atomic Red Team-style tests for OS credential dumping used to generate labeled detection data.
Credential dumping tool referenced in Sigma detection examples for identifying malicious driver loads or credential theft activity.
Credential dumping utility used to extract password hashes/credentials from Windows sources including SAM, LSA secrets, AD, and logon sessions.
Credential dumping tool used to extract Windows password hashes from the SAM database.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.