Pinch, also known as LdPinch, is a Windows credential-stealing malware family historically associated with theft of stored account data from compromised systems. It is best characterized as an infostealer focused on harvesting credentials rather than a general-purpose remote access platform. Reported functionality includes stealing credentials from infected hosts, and its codebase has been assessed as the basis for the credential-theft component used by PinchDuke. Pinch-related detections have also appeared under trojan naming conventions in antivirus products. High-confidence reporting ties the malware to credential access activity on Windows systems, but the available information here does not support more specific conclusions about delivery vectors, persistence mechanisms, or broader post-compromise behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an antivirus detection name applied to the sample, not as the actual malware under analysis.
Credential stealing malware referenced as the source-code basis for PinchDuke's credential theft functionality.
Credential stealing malware referenced as the code basis for PinchDuke.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.