HOMEFRY is a credential-dumping utility associated with China-linked espionage activity, particularly operations attributed to APT40, also known as Leviathan. It has been described as a password dumper and cracker used to obtain password hashes and other credential material from compromised systems. The tool exposes a command-line interface and is employed as part of post-compromise credential access workflows rather than as a standalone initial access mechanism. In reported intrusions, HOMEFRY has been used alongside other APT40 tooling, including backdoors such as AIRBREAK and BADFLICK, to support broader espionage objectives. APT40 has historically targeted engineering, transportation, defense, and maritime-related organizations, as well as other entities aligned with Chinese strategic intelligence requirements. The available information supports HOMEFRY as a Windows-focused credential theft utility used to dump credentials from victim hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HOMEFRY can perform credential dumping. Leviathan has used publicly available tools to dump password hashes, including HOMEFRY.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims... BlackByte used tools such as Cobalt Strike and Mimikatz to dump credentials from victim systems... Storm-0501 has used the SecretsDump module within Impacket can perform credential dumping to obtain account and password information.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool that can dump credentials and password hashes from victim systems.
Custom password dumping/cracking utility used to harvest credentials and escalate privileges.
Tool capable of dumping credentials from victim systems.
Malware/tool that uses a command-line interface for operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.