Quarks PwDump is a Windows password-dumping utility used to extract multiple types of Windows credentials from compromised systems. It has been documented since at least 2013 and is frequently associated with Chinese espionage-linked intrusion activity. Reported use includes operations by APT15/Ke3chang, where it was deployed alongside other post-compromise tooling to dump credentials and support follow-on access.
The tool is used for credential theft during post-exploitation, enabling operators to obtain locally stored or otherwise accessible Windows credential material for privilege escalation, lateral movement, and persistence of access within victim environments. It has been observed in campaigns targeting diplomatic and foreign affairs organizations, including activity attributed to APT15. Detection reporting has also noted that it creates temporary dump files on Windows hosts, which can provide host-based forensic and detection opportunities.
Quarks PwDump is best characterized as a credential-dumping utility rather than a full-featured backdoor or loader. Public reporting in the supplied material does not establish a specific initial delivery vector for the tool itself; instead, it appears as an operator-deployed component used after compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Quarks PwDump – Dumps different types of Windows credentials. Documented since 2013.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Quarks PwDump is new open source tool to dump various types of Windows credentials: local account, domain accounts, cached domain credentials and bitlocker.
Hashes are extracted live from SAM and SECURITY hive in a proper way without code injection/service.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows credential dumping utility (documented since 2013) used to extract multiple credential types.
A password-dumping tool used by Okrum operators for credential dumping.
Credential/password dumping tool that creates temporary dump files (e.g., SAM-related .dmp files in user temp paths) which can be detected via Sysmon file creation events (EventID 11).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.