Security researchers highlighted multiple Windows credential exposure paths that can hand attackers plaintext passwords without requiring noisy LSASS dumping. Common sources include PowerShell command history stored in ConsoleHost_History.txt, plaintext files and stealer logs, exposed Active Directory attributes, and legacy Group Policy Preferences (GPP) XML files in SYSVOL that may still contain decryptable cpassword values accessible to authenticated domain users.
The reporting also described more persistent credential-harvesting techniques that abuse legitimate Windows authentication components, including malicious Security Support Providers, password filter DLLs, and network provider DLLs to capture credentials during logon or password changes. Defenders were urged to remove vulnerable GPP artifacts, deploy protections such as Microsoft's LAPS, audit systems for exposed secrets and suspicious registry or file changes, and monitor for abuse of PowerShell history and authentication-related components with tools such as Sysmon.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Volexity published research describing active exploitation of two zero-day vulnerabilities affecting Ivanti Connect Secure VPN appliances. This is a separate incident from the existing Group Policy Preferences timeline and represents the first documented event for this new story in the provided materials.
Microsoft released security update MS14-025/KB2962486 to address the Group Policy Preferences password problem. The update blocked administrators from creating new password-bearing GPP entries but did not remove existing exposed XML files from SYSVOL.
Chris Campbell published "GPP Password Retrieval with PowerShell" and created early PowerShell code to recover passwords from vulnerable Group Policy Preferences data.
Alexandre Herzog also published documentation describing exploitation of credentials stored in Windows Group Policy Preferences.
Emilien Gauralt wrote about exploiting Windows 2008 Group Policy Preferences, documenting how stored credentials could be abused.
Microsoft acquired DesktopStandard's PolicyMaker in 2006 and later rebranded it as Group Policy Preferences in Windows Server 2008, laying the groundwork for the later GPP password exposure issue.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
7 references tracked. Mallory keeps watching after this page renders.
dfir.ch
Open sourcedfir.ch
Open sourceasec.ahnlab.com
Open sourcenextron-systems.com
Open sourcevolexity.com
Open sourceblog.ecapuano.com
Open sourceadsecurity.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.