SecHack is a Windows credential theft utility used to extract passwords from lsass.exe memory on both 32-bit and 64-bit systems. It is described as similar to Mimikatz's sekurlsa::logonpasswords functionality and was used by TEMP.Veles during the C0032 campaign alongside Mimikatz to harvest credentials. SecHack queries the msv1_0, kerberos, wdigest, and tspkg authentication packages. It must be run with elevated privileges and does not include its own persistence mechanism, requiring an external installer or tool for persistence. In addition to credential dumping, it can collect host information and installed certificate information via optional "info" and "cert" parameters. The "info" option collects OS version and full version, Product Name, Processor Architecture, UAC Admin flags, and current process attributes. The "cert" option collects certificate store, subdir, name, container, provider, keyspec, key size, key exportable, and pfx information. If executed in a 64-bit process context, it writes a 64-bit version of itself to the same path with a ".x64" extension. Its output is JSON and begins with the string "SecHack 1.0 by OSA". A referenced sample is KB77846376.exe (MD5: 47f9cc543905a69a423f9110ae7deffb), which contains a 64-bit version of itself as resource "IDR_MOD1" (MD5: ee477fdee8b6ad4fe778a6fa4058f9aa).
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom credential-harvesting tool used alongside Mimikatz for credential collection.
Credential theft tool that extracts credentials from LSASS memory (similar to Mimikatz sekurlsa::logonpasswords). Can also enumerate OS/process attributes and installed certificates; requires elevated privileges; no built-in persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.