DumpItForLinux
DumpItForLinux is a Linux memory acquisition and credential-access tool observed in Palo Alto Networks Unit 42 reporting on the Chinese-linked threat cluster CL-UNK-1068. In the reported intrusions, the actor operated across both Windows and Linux environments and used DumpItForLinux together with the Volatility Framework to extract password hashes from memory. The broader campaign was described as a years-long operation affecting organizations in South, Southeast, and East Asia, including telecommunications, energy, technology, pharmaceutical, government, law enforcement, and aviation sectors, with activity assessed as strongly suggestive of espionage. DumpItForLinux was part of a credential-theft toolkit that also included Mimikatz, LsaRecorder, and the SQL Server Management Studio Password Export Tool. The provided content does not include specific indicators of compromise unique to DumpItForLinux.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Other tools powering CL-UNK-1068's credential theft activities include Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and the SQL Server Management Studio Password Export Tool.
Techniques & procedures
1 distinct technique documented for this family, organized by ATT&CK tactic.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux memory acquisition tool used to support credential theft/forensic-style collection by enabling memory dumping for offline analysis.
Linux memory acquisition tool used to capture memory for offline analysis (e.g., credential/hash extraction).
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.