Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...hosting an open-source, distributed password cracking management system called Hashtopolis.
...hosting an open-source, distributed password cracking management system called Hashtopolis.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
we also observed tools for additional credential harvesting, including dumping encrypted credentials from the Active Directory
By running parallel jobs through the open source framework Hashtopolis, the attackers were able to process massive volumes of stolen data... Legacy Fortinet Hashes... a 36 GPU cluster... capable of processing up to 720 Billion raw hashes every single second.
Modern Fortinet Hashes (PBKDF2)... the distributed cluster still produced a combined output of roughly 180 Million to 360 Million hashes per second. This allows attackers to run massive, highly targeted dictionary and rule based attacks against internal network credentials in seconds.
attackers "processed 1.16 billion credential attempts against 320,777 FortiGate targets and 2.1 billion attempts against 163,650 MSSQL servers,"
The group reportedly intercepted SSL VPN authentication hashes and cracked them using a 45-GPU cluster managed through Hashtopolis.
“They intercept SSL VPN authentication, crack hashes on a 45-GPU cluster managed via Hashtopolis, and pivot into internal Active Directory environments,” Diachenko says.
ad_full_audit.py enumerates SPN-bearing accounts; Harvester extracts TGS/Kerberos material and cracking infrastructure supports Kerberos formats.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.