Mimikatz is a publicly available, dual-use Windows credential-extraction and post-exploitation tool widely used by penetration testers, state-sponsored threat actors, and financially motivated attackers. It extracts plaintext passwords and password hashes from LSASS memory, retrieves credentials protected by Windows Credential Vault and DPAPI, and supports DCSync-based retrieval of Active Directory account hashes. Its cryptographic functionality can extract certificates and private keys from Windows certificate stores. Mimikatz also supports pass-the-hash impersonation and Kerberos ticket operations, enabling attackers to use compromised identities to access additional systems and privileged enterprise resources.
Mimikatz includes account-manipulation functions that change password hashes without knowing the existing plaintext password. Its Skeleton Key functionality patches LSASS on an Active Directory domain controller so that an attacker-controlled master password is accepted for valid domain accounts while legitimate passwords remain usable. This requires existing domain-administrator privileges, operates in memory, and is removed by restarting the affected controller. Driver-assisted functionality can bypass LSA process protection.
Mimikatz is commonly deployed after initial compromise, either directly or through PowerShell implementations and offensive frameworks such as Cobalt Strike and Empire. Documented users include APT28, APT29, APT41, Sandworm Team, and ransomware affiliates associated with Black Basta and RansomHub. Its principal targets are Windows endpoints and Active Directory environments; it is not specific to a single industry or threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).
PowerShell-based reverse shells being dropped to Minecraft client systems ... which they then use to run Mimikatz to steal credentials.
The report identifies CVE-2017-12149 as remote code execution via deserialization involving JMXInvokerServlet and records numerous HTTP GET and POST requests to /invoker/JMXInvokerServlet.
As early as January 2023, APT actors exploited CVE-2022-47966 for initial access to the organization’s web server hosting the public-facing application, Zoho ManageEngine ServiceDesk Plus.
The CSIRT considers it highly probable that JexBoss exploited CVE-2010-0738, an improper-access-control vulnerability affecting the exposed JBoss JMX console through version 5.1.x.
CVE-2015-7501 is identified as a deserialization vulnerability affecting Java environments using Apache Commons Collections, including JBoss-based environments, and as highly likely exploited through JexBoss.
The report lists CVE-2011-4085 among the vulnerabilities highly likely exploited through JexBoss and describes it as a regression of CVE-2010-0738.
The exploitation of ProxyShell in these attacks involves three vulnerabilities: CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207 — the first two were patched in July 2021, while the latter was fixed in May 2021. | Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
shortly afterwards, credential-dumping tool Mimikatz was used to dump credentials from the system.
shortly afterwards, credential-dumping tool Mimikatz was used to dump credentials from the system.
Mimikatz, a tool that allows users to view and save credentials and is often used for post-exploitation activities, was downloaded by PowerShell.
The fileless attack was delivered via Microsoft Word documents that exploited a former zero-day vulnerability in Word, CVE-2017-0199, to install a fileless attack variant of the Helminth Trojan agent. Microsoft released the patch for the vulnerability on April 11, but many organizations have not yet deployed the update.
Уязвимость RoguePlanet, ранее обнаруженная ИБ-исследователем Nightmare Eclipse, получила идентификатор CVE-2026-50656 (7,8 балла по шкале CVSS). Напомним, что проблема связана с возникновением состояния гонки в Microsoft Defender и позволяет повысить привилегии до уровня SYSTEM и выполнить произвольный код на полностью обновленных системах под управлением Windows 10 и Windows 11.
Security researchers, including Unit 42, have documented the use of coercion tools such as PetitPotam (CVE-2021-36942) in actual attacks. Microsoft has issued security advisories acknowledging the exploitation potential of this CVE.
Kaspersky researchers revealed ... the attackers exploit Internet-exposed Fortigate SSL VPN servers unpatched against the CVE-2018-13379 vulnerability ... The FBI and CISA warned ... APT actors scanning for Fortinet SSL VPN appliances vulnerable to CVE-2018-13379 exploits ... Fortinet also warned customers to patch their appliances against the CVE-2018-13379 ... "CVE-2018-13379 is an old vulnerability resolved in May 2019"
Earth Longzhi reimplemented some modules of Mimikatz ... as standalone binaries. ... We call this technique "Bring-Your-Own Mimikatz."
Rapid7’s Incident Response (IR) team was engaged to investigate an incident involving exploitation of CVE-2025-59718 against a vulnerable FortiGate appliance. In December 2025, Fortinet disclosed this improper verification of cryptographic signature vulnerability that facilitates an SSO login bypass on affected appliances.
Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA) ... malicious activity ... consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems exposed to the internet. CVE-2025-32975 (CVSS score: 10.0) refers to an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Previously, Eset reported that about five APT groups has been exploiting the four Exchange vulnerabilities - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065 | "...installed a variety of Mimikatz malware, which is used as a post-exploitation tool to steal passwords from memory..."
Attackers combine this with credential theft (Mimikatz/Pypykatz), lateral movement (Cobalt Strike, SystemBC), and backup destruction to maximize impact and enable double-extortion.
This analytic story covers attacks exploiting CVE-2024-4577, a remote code execution (RCE) vulnerability in the PHP-CGI implementation on Windows. Attackers leverage this vulnerability to gain initial access, deploy Cobalt Strike using the "TaoWu" kit for post-exploitation activities, and establish persistence.
"...a threat actor exploited the CVE-2022-40684 vulnerability to bypass authentication on the organization’s Fortinet VPN and gain initial access. Using various Windows tools and services, including smbexec.py from the Impacket toolkit, the attacker executed commands and moved laterally across the network."
64 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Для проведения разведки они использовали SoftPerfect Network Scanner, а для извлечения учетных данных — Mimikatz.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Actors are also leveraging the opensource tools such as Mimikatz and the CrackMapExec tool to obtain valid account credentials from AD servers (Valid Accounts [T1078]).
Actors are also leveraging the opensource tools such as Mimikatz and the CrackMapExec tool to obtain valid account credentials from AD servers (Valid Accounts [T1078]).
«Запуск PowerShell (T1059.001) с обфусцированной командой (T1027)»
Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password, from the operating system and software.
«Masque используют инструменты Mimikatz, procdump и comsvcs.dll для извлечения памяти процесса LSASS.»
Actors dumped sam.hiv to obtain information about users on the system.
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
APT15 uses widely accessible tools like Mimikatz and LaZagne (T1003.001, T1003.004, T1003.005).
APT15 uses widely accessible tools like Mimikatz and LaZagne (T1003.001, T1003.004, T1003.005).
Monitor domain controller logs for replication requests and other unscheduled activity possibly associated with DCSync.
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
139 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Offensive credential-extraction tool used by ransomware affiliates during the interval between initial compromise and encryption.
An offensive credential-dumping tool mentioned as background and comparison with NPPSpy. The article describes its abuse of Windows Security Support Providers and notes that established credential-dumping techniques are commonly detected by antivirus and endpoint detection systems.
Credential-theft tooling used in Akira intrusions to support privileged account compromise and subsequent access to domain controllers, backup servers, and hypervisors.
Named offensive tool leveraged in the reported Silent Chollima campaign. Its specific use is not described.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.