gsecdump is a publicly available Windows credential-dumping utility used to extract password hashes and authentication secrets from compromised systems. It can harvest credentials from the Security Account Manager (SAM), Local Security Authority (LSA) secrets, Active Directory, and logon sessions. Its credential-access behavior falls under OS Credential Dumping, including the SAM and LSA Secrets sub-techniques.
Adversaries deploy gsecdump during post-compromise operations to obtain authentication material that can support expanded access within victim environments. Documented users include Tick, also known as BRONZE BUTLER, Ke3chang, PittyTiger, Threat Group-3390, TaskMasters, and Earth Akhlut. It was also used during the Night Dragon campaign. Tick has deployed it alongside Mimikatz and Windows Credential Editor in espionage operations targeting Japanese technology, engineering, and media organizations. gsecdump is a credential-extraction tool rather than a self-propagating or independently delivered malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool referenced as part of Atomic Red Team-style tests for OS credential dumping used to generate labeled detection data.
Credential dumping tool referenced in Sigma detection examples for identifying malicious driver loads or credential theft activity.
Credential dumping utility used to extract password hashes/credentials from Windows sources including SAM, LSA secrets, AD, and logon sessions.
Publicly available offensive tool acquired and used by several groups; no functionality is detailed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.