Hashcat is a GPU-based password cracking utility used for offline cracking of password hashes. In the provided content, it is referenced as being used by threat actors in the FortiBleed campaign after custom tooling harvested authentication material from compromised Fortinet FortiGate devices. According to the reporting cited, attackers generated Hashcat-ready files containing NTLM and Kerberos hashes, then used distributed GPU infrastructure to crack those hashes at scale; one account also states hashed credentials from downloaded FortiGate configuration files were cracked with Hashcat using 36 enterprise-class GPUs. The content also references Hashcat more generally as a hash-cracking tool used by adversaries to crack stolen passwords after obtaining hashes. High-confidence details in the content characterize Hashcat as a legitimate password cracking utility rather than bespoke malware; no malware-specific infection vector, persistence mechanism, or native indicators of compromise are provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-27903 - A vulnerability in the plugin mechanism leading to RCE in Windows, and LPE and data manipulation in Android, iOS, macOS, and BSD
CVE-2024-27459 - A stack overflow vulnerability leading to a Denial-of-service (DoS) and LPE in Windows
CVE-2024-24974 - Unauthorized access to the "\\openvpn\\service" named pipe in Windows, allowing an attacker to remotely interact with it and launch operations on it
CVE-2024-1305 - A memory overflow vulnerability leading to DoS in Windows
14 distinct techniques documented for this family, organized by ATT&CK tactic.
In practice, this means recovering the DES-derived value from the 2nd QSYRUPWD CIPHER block, the SHA-1-related value from the 3rd QSYRUPWD CIPHER block, and the NT hash from the 5th QSYRUPWD CIPHER block.
When attempting to break the ASP.NET Core Identity hashes with Hashcat, we need to ensure that Hashcat correctly identifies the hash type or set it manually with the hash-mode.
On 2,340 endpoints, a named account such as ADMIN or root matched a password sitting in a wordlist anyone can download. Many of those fell on the first pass, within minutes.
Lors de l’échange RAKP, le BMC retourne un code HMAC-SHA1 calculé à partir du mot de passe du compte, accessible à un attaquant non authentifié pouvant joindre UDP port 623. Ce mécanisme permet une attaque par dictionnaire hors ligne sans générer de tentatives de connexion échouées sur le BMC cible.
attackers "processed 1.16 billion credential attempts against 320,777 FortiGate targets and 2.1 billion attempts against 163,650 MSSQL servers,"
In an update published on Friday, cybersecurity expert Kevin Beaumont suggested that the attackers also obtained hashed credentials by downloading FortiGate configuration files from compromised devices. The threat actors then extracted the hashed credentials and cracked them using Hashcat and 36 enterprise-class GPUs.
I turned on Responder and waited for svc.scanner to process my file... I saved the hash and cracked it using Hashcat.
The four attacks we will demonstrate are: Weak Password Hashing : Cracking NTLM hashes to recover plaintext passwords Pass-the-Hash : Authenticating with only the hash, no plaintext password required Kerberoasting : Extracting and cracking service account credentials Golden Ticket : Forging Kerberos tickets to impersonate any user
Kerberoasting : Any authenticated domain user can request service tickets for accounts with registered SPNs. These tickets are encrypted with the service account's password hash and can be cracked offline, often revealing weak service account passwords.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A GPU-based password cracking utility used by the threat actors to crack NTLM and Kerberos hashes and other harvested credential material at scale using distributed GPU infrastructure.
GPU-accelerated offline password cracking tool used to recover plaintext passwords from dumped hashes.
GPU-accelerated offline password hash cracking tool used after credential dumping to recover passwords from hashes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.