Kerbrute is an open-source Kerberos enumeration and password-spraying tool used against Active Directory environments. It is commonly employed to validate usernames, enumerate domain accounts, and perform brute-force or password-spray activity over Kerberos without relying on SMB or other noisier protocols. In intrusion operations it is typically used as post-compromise or lateral-movement support tooling rather than as a standalone malware payload.
Observed use places Kerbrute in Windows-centric enterprise attack chains targeting Active Directory. It has appeared alongside other offensive utilities used for internal reconnaissance, NTLM- and Kerberos-focused movement, credential access, and relay-style attacks. Reported activity includes use by threat actors operating from compromised Linux staging hosts against Windows infrastructure, as well as inclusion in toolsets associated with espionage clusters attributed with moderate confidence to Chinese state-linked actors, including activity associated with Alloy Taurus. In these cases, Kerbrute supported identity-focused operations against domain environments after initial footholds were established through other means.
Kerbrute is best characterized as a dual-use offensive security tool or hacktool rather than a conventional self-propagating malware family. Its primary security relevance lies in credential attacks and Active Directory reconnaissance, especially username discovery and password spraying against Kerberos-enabled services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Key indicators include the C2 address 206.189.27[.]39 and file hashes for the custom scanner, Kerbrute, gowitness, and an NTLM relay script.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
В MITRE ATT&CK обе техники живут под T1110 (Brute Force): credential stuffing - T1110.004, password spraying - T1110.003.
"There are two main types of trial-and-error attacks on passwords: Brute-force attacks: attempts to log on to a given account using several passwords entered one after the other. Passwords can be random or taken from a dictionary of commonly used passwords."
Let’s try password spraying using UserList.txt and the password we found by Kerberoasting... I used crackmapexec and kerbrute for this.
This includes Impacket, KrbRelayX, Coercer, BloodHound.py, NetExec, Kerbrute, and Metasploit... Observed malicious activity included downloading credentials, enumerating Kerberos usernames via Kerbrute...
The threat actor performed extensive reconnaissance of the host and network, including file enumeration, network scanning, and service discovery. They aggressively scanned the internal network subnets with Nmap to identify connected hosts, and then used Nmap on the identified hosts to detect open services.
Where Windows servers were discovered, the actor attempted NTLM-based lateral movement using a familiar open-source toolkit, including enum4linux, netexec, smbclient, rpcclient, timeroast, ldapsearch, kerbrute, and responder, though these initial attempts failed.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kerbrute was used as part of the actor’s NTLM/Kerberos-focused lateral movement and credential attack activity against Windows infrastructure and Active Directory.
An open-source tool used in this intrusion for Kerberos/Active Directory-focused enumeration and authentication abuse during lateral movement and privilege escalation attempts.
An open-source tool used for Kerberos-focused enumeration and authentication abuse during lateral movement and privilege escalation attempts against Active Directory.
Tool used to enumerate and/or brute-force Active Directory accounts via Kerberos, supporting credential access and discovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.