Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This was performed using several open-source utilities, including nanodump and mimikatz.
The actual SSP loaded is NanoDump, which is loaded into LSASS and creates a minidump of the process. Loading NanoDump as an SSP is a built-in function embedded within NanoDump.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Scenario 1 - Credential Dump I attempted a credential dump using the well-known tool Mimikatz, as well as a manually obfuscated commonly used credential dump tool, NanoDump.
T1003.001 – OS Credential Dumping: LSASS Memory The adversary dumped Local Security Authority Subsystem Service (LSASS) memory several times across multiple systems... using several open-source utilities, including nanodump and mimikatz. | the adversary leveraged the mimikatz tool, ‘m.exe’, to access additional valid credentials... The binary was used on multiple hosts to dump the memory of the LSASS process
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commonly used credential-dumping tool designed to dump LSASS memory, often used in evasive or obfuscated form.
An LSASS dumping tool used here as the credential dumping payload. It is loaded as an SSP into LSASS and creates a minidump using MiniDumpWriteDump, allowing credential harvesting from compromised systems.
Nanodump is a credential-dumping tool used to dump credentials from the LSASS process via multiple dumping methods, including its own implementation of MiniDumpWriteDump.
nanodump was used to dump LSASS memory and obtain cached credentials on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.