Responder is an open-source, dual-use credential-harvesting and adversary-in-the-middle tool used in penetration testing and malicious intrusions. It poisons Link-Local Multicast Name Resolution (LLMNR), NetBIOS Name Service (NBT-NS), and multicast DNS (mDNS) responses to redirect local-network clients to attacker-controlled services. It captures usernames, password hashes, and other credentials submitted by redirected clients, particularly NTLM authentication material in Windows and Active Directory environments. Responder has also been used to abuse Windows Proxy Auto-Discovery (WPAD) for NTLM credential capture. Its name-resolution poisoning behavior maps to MITRE ATT&CK sub-technique T1557.001.
APT28 has deployed Responder for NetBIOS name-service poisoning and credential harvesting. Since at least 2022, the group has also installed Responder alongside Impacket's NTLM relay tooling on compromised Linux-based Ubiquiti EdgeRouters, using rogue authentication services to collect NTLMv2 authentication material leaked through exploitation of Microsoft Outlook vulnerability CVE-2023-23397. Responder supplies credential capture within this workflow, while the accompanying relay tooling supports authentication relay. Lazarus Group has used Responder for local-network credential harvesting, including LLMNR/NBT-NS poisoning in Operation Bookcodes, and obtained it for Operation Dream Job. The tool has additionally appeared in telecommunications espionage intrusions, including activity tracked as CL-STA-0969. Responder is not inherently malware; its malicious use depends on the operator and deployment context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
APT28 actors have used ntlmrelayx.py and Responder to facilitate NTMLv2 credential leaks via exploitation of CVE-2023-23397 as a zero-day vulnerability since early 2022.
These behaviors indicate that the server may have installed an LLMNR poisoning tool, such as Responder.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Credential Access T1557.001 — Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning ntlmrelayx, Responder.”
APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.
...using a mix of custom and public tools such as Microsocks, FRP, FScan, and Responder...
19 distinct techniques documented for this family, organized by ATT&CK tactic.
A specially crafted .lnk file, when embedded in a .zip archive and previewed in Windows Explorer, causes the system to silently attempt to retrieve a remote icon over SMB.
APT28 actors have installed publicly available tools such as Impacket ntlmrelayx.py and Responder on compromised Ubiquiti routers to execute NTLM relay attacks [T1557].
« empoisonnement LLMNR/NBT-NS, capture NTLM via Responder »
«-D поднимает SOCKS5-прокси. Браузер и proxychains через него работают, но Responder, ARP-спуфинг, ICMP-сканирование — нет».
APT28 actors have installed publicly available tools such as Impacket ntlmrelayx.py and Responder on compromised Ubiquiti routers to execute NTLM relay attacks [T1557].
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive tool mentioned briefly as an established means of obtaining credentials in Active Directory networks. The article provides no further details about its operation or use in a specific campaign.
Credential-capture tool explicitly incorporated into Putnik's internal network attack capabilities for capturing NTLM authentication material.
A network poisoning and credential-capture tool used for LLMNR/NBT-NS attacks and NTLM credential interception.
Credential harvesting tool used for LLMNR/NBT-NS/MDNS poisoning and capture of authentication material.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.