SniffPass is a Windows credential-sniffing utility from NirSoft that captures passwords transmitted over insecure application protocols by monitoring network traffic. It is not a full malware family in itself, but it has been used as an offensive credential-access tool by state-linked intrusion sets including APT33 and Kimsuky. In reported intrusions, operators used SniffPass to passively inspect network communications and recover credentials sent in cleartext or otherwise exposed over non-secure protocols. Its observed role is focused on credential collection during post-compromise activity rather than initial access or persistence. Because it is a legitimate dual-use network sniffer, its presence is most significant when correlated with broader intrusion activity involving espionage-oriented threat actors and credential theft objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Symantec has the following protection in place to protect customers against Elfin attacks: ... SniffPass
Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
logs indicate that an attacker remotely connected and installed the password-sniffing tool Mimikatz... The attackers also attempted to gather credentials using a different tool called LaZagne.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Password recovery/credential theft tool listed in protections against Elfin attacks.
Password theft tool used by Elfin to capture credentials from network traffic.
Network sniffer used to capture credentials/passwords sent over non-secure protocols by monitoring network traffic.
Network password sniffer used to capture credentials transmitted over cleartext/non-secure protocols.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.