Impacket is an open-source collection of Python modules and utilities for interacting with network protocols. It is legitimate dual-use software rather than a malware family, but is widely abused for credential theft, remote command execution, reconnaissance, and lateral movement in Windows and Active Directory environments. Its utilities support remote semi-interactive shells through Windows Management Instrumentation and Server Message Block, credential dumping, Kerberos manipulation, and authentication relay attacks.
Impacket can extract credential material from the Windows Security Account Manager and Active Directory databases, including domain password hashes. Its service-principal-name enumeration functionality supports Kerberoasting by obtaining ticket material suitable for offline password cracking with external tools. Remote execution utilities allow operators using compromised credentials to execute commands on other systems; some redirect command output into temporary files accessed through administrative shares.
Documented users include menuPass, FIN7, Volt Typhoon, BianLian, Masque, and LockBit affiliates. Its abuse spans espionage, domain compromise, and ransomware operations, including lateral movement preceding Clop and other ransomware deployments. Operators install or transfer the toolkit into compromised environments, and executable-packaged versions of individual utilities have also been observed. Impacket use alone does not establish malicious activity or attribution to a particular threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The operator deployed a standalone Linux build of Impacket’s secretsdump directly onto selected SonicWall appliances, enabling remote credential theft from internal Windows systems.
Post-exploitation : Impacket , attaques NTLM relay, mouvement latéral
A working proof-of-concept (PoC) exploit has been released for a new NTLM reflection bypass flaw that enables SYSTEM-level access on Windows Server 2025. The vulnerability, tracked as CVE-2026-24294, abuses a feature introduced in Windows 11 24H2 and Windows Server 2025 that allows SMB connections over arbitrary TCP ports.
Impacket is a versatile, dual-use tool that uses Python-based scripts to exploit legitimate Windows services and protocols... threat actors frequently use psexec.py, smbexec.py, and wmiexec.py scripts within Impacket to execute code remotely on Windows systems without additional payloads or tools.
56 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump.
They then use OpenSSH and Impacket to move laterally and deploy Clop ransomware.
menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump.
menuPass has used and modified open-source tools like Impacket, Mimikatz, and pwdump.
FortiGuard Labs provides the following AV coverage for the available samples used in the attack: ... Riskware/Impacket ...
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The adversary used impacket to execute Windows Management Instrumentation (WMI) to achieve command execution on other systems present in the environment.
Covers wmiexec, smbexec, and atexec modules. ... selection_atexec ... ParentImage|endswith: '\svchost.exe', '\taskeng.exe'.
Actors abused command and script interpreters to execute commands.
BianLian group actors used Windows Command Shell to disable antivirus tools, for discovery, and to execute their tools on victim networks.
ESET telemetry shows Spacecolon operators executing both scripts directly through Impacket.
Covers wmiexec, smbexec, and atexec modules. ... selection_atexec ... ParentImage|endswith: '\svchost.exe', '\taskeng.exe'.
Covers wmiexec, smbexec, and atexec modules. ... selection_atexec ... ParentImage|endswith: '\svchost.exe', '\taskeng.exe'.
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and access rights.
The command history shows the installation and execution of tools targeting Windows authentication and Active Directory, including Responder, NTLM relay-related tools, Impacket, and NetExec.
They then used NetExec and Impacket to attempt authentication to services such as SMB, LDAP, RDP, and WinRM, seeking access to multiple hosts and attempting lateral movement.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
133 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Dual-use tooling associated with remote command execution in the incident. Temporary command-output filenames and loopback ADMIN$ destinations are described as consistent with Impacket execution, particularly wmiexec.py; this is an artifact-based association rather than confirmation of a recovered Impacket sample.
An offensive network-protocol and remote-execution toolkit used in this case to transfer and launch the NeedyMantis deployment package after an attacker had obtained network access.
Impacket is a toolkit used during observed hands-on-keyboard follow-on activity to transfer and execute the NeedyMantis deployment package after initial access. The content does not describe it as a NeedyMantis component or as the primary malware.
Dual-use offensive security tooling used by Storm-2570 for remote execution as it spreads to additional machines in compromised networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.