Hashtopolis
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...hosting an open-source, distributed password cracking management system called Hashtopolis.
...hosting an open-source, distributed password cracking management system called Hashtopolis.
Techniques & procedures
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Persistence
1 technique
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Stealth
1 technique
Stealth
Credential Access
9 techniques
Credential Access
we also observed tools for additional credential harvesting, including dumping encrypted credentials from the Active Directory
the broader collection reveals the working data of a live, multi-server initial access operation that was brute-forcing not only Fortinet VPN logins, but also gaining access to other accounts and edge devices including Synology NAS devices, Sophos firewalls, and MSSQL servers.
Для взлома перехваченных хешей использовался кластер из 45 GPU под управлением Hashtopolis...
attackers "processed 1.16 billion credential attempts against 320,777 FortiGate targets and 2.1 billion attempts against 163,650 MSSQL servers,"
The group reportedly intercepted SSL VPN authentication hashes and cracked them using a 45-GPU cluster managed through Hashtopolis.
“They intercept SSL VPN authentication, crack hashes on a 45-GPU cluster managed via Hashtopolis, and pivot into internal Active Directory environments,” Diachenko says.
ad_full_audit.py enumerates SPN-bearing accounts; Harvester extracts TGS/Kerberos material and cracking infrastructure supports Kerberos formats.
Collection
1 technique
Collection
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.