MimiPenguin is an open-source Linux credential-dumping tool modeled after the credential access functionality popularized by Mimikatz on Windows. It is designed to dump process memory and recover passwords and authentication material from Linux user-space processes, making it useful for post-compromise credential theft on Linux systems. Security reporting and ATT&CK-aligned detections describe it as harvesting passwords and hashes from memory and as a Linux adaptation used for credential dumping from running processes.
The tool has been observed in real-world intrusion activity associated with TeamTNT, a threat actor focused on Linux servers, containers, and cloud environments. In those operations, MimiPenguin was used alongside Mimipy to extract credentials from compromised Linux hosts as part of broader campaigns involving cryptomining, cloud credential theft, lateral movement, and persistence. Its use is consistent with post-exploitation workflows in which attackers seek reusable credentials after gaining access to exposed infrastructure such as Docker, Kubernetes, and other internet-facing Linux environments.
MimiPenguin primarily targets Linux platforms and is relevant to enterprise servers, cloud workloads, and containerized environments where in-memory credentials may be exposed through user sessions or authentication-related processes. It is commonly treated as a credential-dumping utility rather than a standalone malware family with its own propagation or command-and-control features.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The tool exploits a known vulnerability CVE-2018-20781.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the researchers reported on uses of mimipenquin and mimipy by the threat actor. Both of these tools are designed to dump passwords from various processes’ memory.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux credential-dumping tool/script; content ties detections to credential dumping activity and references CVE-2018-20781 in relation to Mimipenguin.
An open-source credential dumping tool for Unix-like systems used by TeamTNT to extract passwords from memory.
Linux credential dumping tool that scrapes process memory for passwords/hashes using string/regex matching.
Software changes: ... MimiPenguin
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.