Remote Desktop PassView is a NirSoft credential-dumping utility for Windows that extracts account information saved in Remote Desktop Protocol (RDP) settings on a machine. The content identifies the executable as rdpv.exe and describes it as extracting credentials or related account data stored in RDP client configuration. It is referenced alongside other password-dumping tools used by attackers to export client credentials. The provided content is focused on forensic detection and states that execution may be evidenced through process creation telemetry such as Sysmon Event ID 1 and Windows Security Event IDs 4688/4689, as well as execution artifacts such as Prefetch where available. However, it also explicitly notes that successful extraction cannot be reliably confirmed from logs alone unless the dumped passwords are saved to an output file. No specific threat actor, industry targeting, or infection vector is provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.