Hashcat is a GPU-based password cracking utility used for offline cracking of password hashes. In the provided content, it is referenced as being used by threat actors in the FortiBleed campaign after custom tooling harvested authentication material from compromised Fortinet FortiGate devices. According to the reporting cited, attackers generated Hashcat-ready files containing NTLM and Kerberos hashes, then used distributed GPU infrastructure to crack those hashes at scale; one account also states hashed credentials from downloaded FortiGate configuration files were cracked with Hashcat using 36 enterprise-class GPUs. The content also references Hashcat more generally as a hash-cracking tool used by adversaries to crack stolen passwords after obtaining hashes. High-confidence details in the content characterize Hashcat as a legitimate password cracking utility rather than bespoke malware; no malware-specific infection vector, persistence mechanism, or native indicators of compromise are provided.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-27903 - A vulnerability in the plugin mechanism leading to RCE in Windows, and LPE and data manipulation in Android, iOS, macOS, and BSD
CVE-2024-27459 - A stack overflow vulnerability leading to a Denial-of-service (DoS) and LPE in Windows
CVE-2024-24974 - Unauthorized access to the "\\openvpn\\service" named pipe in Windows, allowing an attacker to remotely interact with it and launch operations on it
CVE-2024-1305 - A memory overflow vulnerability leading to DoS in Windows
15 distinct techniques documented for this family, organized by ATT&CK tactic.
In practice, this means recovering the DES-derived value from the 2nd QSYRUPWD CIPHER block, the SHA-1-related value from the 3rd QSYRUPWD CIPHER block, and the NT hash from the 5th QSYRUPWD CIPHER block.
«Monitor mode переводит адаптер в режим пассивного прослушивания всего Wi-Fi-трафика в радиусе действия — без него не захватишь WPA2 handshake и не проведёшь разведку эфира».
...including RAKP hash capture from IPMI/BMC interfaces (drop it straight into Hashcat mode 7300)...
“I started with some brute forcing up to 9 characters... I left some brute force tasks running over the weekend.”
“The LLM Mask Attack, which describes the passwords you expect in English and turns that into hashcat masks.” | “The workflow that made it worth building: 1. Run a normal rule-based attack with --debug-mode 5 ... Build a trimmed rule file from those top rules and run it against the remaining uncracked hashes.” | “It explains rules. Give it a rule and a baseword and it walks you through the transformation one operation at a time.”
«Через --stdout он способен читать произвольные файлы. Если на целевой машине hashcat стоит с SUID-битом — это вектор для Credentials In Files (T1552.001)».
I turned on Responder and waited for svc.scanner to process my file... I saved the hash and cracked it using Hashcat.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A GPU-based password cracking utility used by the threat actors to crack NTLM and Kerberos hashes and other harvested credential material at scale using distributed GPU infrastructure.
GPU-accelerated offline password cracking tool used to recover plaintext passwords from dumped hashes.
GPU-accelerated offline password hash cracking tool used after credential dumping to recover passwords from hashes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.