Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers were seen using an open-source tool called DonPAPI that can locate and dump credentials stored using the Windows Data Protection API (DPAPI).
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Akira operators aggressively pursue credential access using Mimikatz and the DonPAPI toolkit to harvest passwords from Windows credentials, cached browser passwords, RDP/VNC logins, LSASS memory dumps, SAM database extraction, and NTDS.dit copying from domain controllers.
Take DonPAPI, for example. This is an open-source tool observed in several recent Talos IR engagements that automates credential dumping remotely on multiple Windows computers. It locates and retrieves Windows Data Protection API (DPAPI) protected credentials, a process also known as “DPAPI dumping.” DonPAPI searches for certain files, including Wi-Fi keys, RDP passwords and credentials saved in web browsers
If the tool is executing from a non-domain joined host (aka Linux), an SMB connection is initiated and then contents of the Local State file are read in order to decrypt the AES key before concluding the attack with the decryption of the passwords stored in the Login Data.
The master keys file can be imported to dploot, a python implementation of SharpDPAPI, in conjunction with the browser flag. The tool will authenticate with the target host via SMB and will dump credentials and cookies stored in Microsoft Edge and Google Chrome.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A tool used to collect and decrypt DPAPI-protected credentials and secrets from Windows environments.
Remote DPAPI credential-dumping tool listed among projects associated with the affiliate's GitHub activity. No specific execution or victim compromise is documented.
An open-source tool that automates remote DPAPI credential dumping across Windows systems, retrieving items such as Wi-Fi keys, RDP passwords, and browser-saved credentials to support authentication and lateral movement.
A post-exploitation credential theft tool capable of performing DPAPI-related operations similar to dploot and SharpDPAPI against remote Windows hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.