Malware

MimiKatz

Varonis summarizes Mimikatz as an open-source application that allows users to view and save authentication credentials like Kerberos tickets. Benjamin Delpy continues to lead Mimikatz developments, so the toolset works with the current release of Windows and includes the most up-to-date attacks. Attackers commonly use Mimikatz to steal credentials and escalate privileges: in most cases, endpoint protection software and anti-virus systems will detect and delete it. Conversely, pentesters use Mimikatz to detect and exploit vulnerabilities in your networks so you can fix them.

Indicators of Compromise 100

Filename !light.bat Filename HRSword.exe Filename HRSword.lnk Filename MyAppDomainManager.dll Filename PerfWatson2.exe Filename TeamViewer_Host_Setup – <encryptor_2>.exe Filename anydesk.exe Filename chrome_setup.zip Filename dark.sys Filename encrypter-windows-gui-x86.exe Filename encryptor_1.exe Filename encryptor_2.exe Filename g11.sys Filename netscan.exe Filename pars.vbs Filename psexesvc.exe Filename result.txt Filename symantec.exe GitHub Repo TalosIntel/IOCs MD5 19f8befcb035f52bf70094e6b4f5779a MD5 64e9d1950e42bc98486dfd9919463d1c MD5 64e9d195e42bc98486dfdd9919463d1c MD5 7f223ee0716ce2ad56f55d3744419449 MD5 846ef7c1c7323849b2a778c5e4cda162 MD5 93a1569d5d5ab2c4761fedf84f83709e MD5 cb6c4c70a3b171fa3404b8e1a3382116 MD5 cbbb6d483737ea3566726e51752dff40 MD5 d08a059e8b815e3b891505bc8777fc28 MD5 d6e86bf8a90e9b632add5fa495f97fbc MD5 dc506ff7bb72735444fb3703a6bee6d8 MD5 ebffd5a76aaa690bcdb922f82e0bacc5 SHA-256 00e09754526d0fe836ba27e3144ae161b0ecd3774abec5560504a16a67f0087c SHA-256 0ce7badb26174b6129fb13d7e255e582f84d8aaedeabcd02c80d84a609144e68 SHA-256 1588023393eb6b4d9433d539d303ecb56b6c3630e860f94d1a137834bdedf2bd SHA-256 207b11f7dc4f17e4e5a9c25dbfb6a785a7456d7c381ecea7c729d8d924be1fb9 SHA-256 274ca13168b38590c230bddc2d606bbe8c26de8a6d79156a6c7d07265efe0fdf SHA-256 2b214bddaab130c274de6204af6dba5aeec7433da99aa950022fa306421a6d32 SHA-256 2d91a78e739891c9854c254f5b2a6b84c0e167dfa253466cbccd2cdd1c20145d SHA-256 396aa1f8f308010a3c76a53965d0eddd35e41176eacd1194745d9542239ca8dc SHA-256 4a44d0c6cf5de515dd296f05ff6674d1a340fccf6b4c11612d27be2d3baa82b0 SHA-256 4adbb1906762c757764ffc5fa64af96e091966f4f5a43aae12fcc4f05f1c26b5 SHA-256 4e1f8888d020decd09799ec946f1bf677cac6612b24582ddbf4d8ede425d8384 SHA-256 5be325905df8aab7089ab2348d89343f55a2f88dadd75de8f382e8fa026451bd SHA-256 647b2f12486343fe065dc4abbb11e2338589eb099c72792b5a05e64a5e2937fc SHA-256 6688fb3039ad6df606d76a897ef1072cdc78b928335c6bfa691d99498caf5c4b SHA-256 6bac99f56e54d5195783513ae6954a4a8509d7bc397c94f405266b5df9cd96cb SHA-256 6ce228240458563d73c1c3cbbd04ef15cb7c5badacc78ce331848f5431b406cc SHA-256 73cd405b5bfc99ec5cf33467d4be7fc7e39ae18337568ee10173c17ba6e8f0d7 SHA-256 771de264c5d7e1e5ac85f00c42e9fe3b439bcbd4f9aa11e4fd7bc0d87fa2344e SHA-256 87bf4b152d9548f415f12f353f988b5442729e7f24e2902ddfd0baa4a944354a SHA-256 8a2f4907159a68867b22bc772590ebcafcfa656a23951228ecd89e4f598472b0 SHA-256 9b481b69cd91b09fa7bae7428f646dd89473a4c03393e43da81fe756cde1c472 SHA-256 b066ca2702853c2fcbf686897c18f6d315be7ae753007ac2c1d73c87b0a30de9 SHA-256 b29f91a440527fb621d106a2048f6379fff3263c60aeda9c82ff8c1d5ae880a8 SHA-256 b3774ba01a3096348fd76a7072407b9f07bb9589e0f5ba31ca576689bbbe94e4 SHA-256 c41216eee9756a1dcc546df4fe97defc05513eed64ce6ac05f1501b50e6f96cc SHA-256 c64964944b4c1f649ae8f694964b3a212dc1028341ab71836306a456fba0b3f4 SHA-256 cbfe8de6ffadbb1d396f61e63eb18e8b11c29527c1528641e3223d4c516cf7c3 SHA-256 d4339a5b9d15211dbc85424cf7fa8ff825033ea3378506d8ecb19b016db5b4ff SHA-256 dce5df29bddff5a4ddaea5c4fec14da91f7b69063a6e1c45ed61e5da4fc6c87b SHA-256 df5a574254637d2880633b0582e956b23f66efc6781e825c65e1ccfaa6c58809 SHA-256 e097f3b445b63b07afacde8d6a67f0be654dd51e228a3610fb0710a1f7e29a69 SHA-256 e8a3e804a96c716a3e9b69195db6ffb0d33e2433af871e4d4e1eab3097237173 SHA-256 eee885e5dae750848d0903d179cacd81149ceecec83c2ec4ad4545531de3cfdf SHA-256 f27eab3157451e31db71169e71f76d28325193218f9dc8f421136d4a20165feb SHA-256 f34bd1d485de437fe18360d1e850c3fd64415e49d691e610711d8d232071a0b1 IP 101[.]36[.]104[.]87 IP 103[.]138[.]13[.]30 IP 139[.]180[.]134[.]221 IP 141[.]95[.]145[.]210 IP 144[.]48[.]6[.]46 IP 15[.]235[.]230[.]188 IP 152[.]32[.]160[.]239 IP 152[.]32[.]222[.]113 IP 162[.]19[.]171[.]150 IP 163[.]172[.]105[.]82 IP 185[.]229[.]191[.]39 IP 202[.]182[.]102[.]5 IP 43[.]106[.]30[.]226 IP 45[.]32[.]113[.]172 IP 45[.]76[.]210[.]43 IP 47[.]80[.]22[.]58 IP 8[.]220[.]193[.]189 IP 8[.]220[.]194[.]108 IP 8[.]220[.]209[.]155 IP 8[.]220[.]214[.]132 Package AnyDesk Package BypassCredGuard Package Chrome Remote Desktop Package Cobalt Strike Package Cyberduck Package Distant Desktop Package GoToDesk Package NirSoft Package QuickAssist Package ScreenConnect Package SharpDecryptPwd Package SystemBC Package WebBrowserPassView Package WinRAR

MITRE ATT&CK TTPs 72

T1001.001
Junk Data
Command And Control
T1003
OS Credential Dumping
Credential Access
T1003.001
LSASS Memory
Credential Access
T1003.002
Security Account Manager
Credential Access
T1018
Remote System Discovery
Discovery
T1021
Remote Services
Lateral Movement
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1021.003
Distributed Component Object Model
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1033
System Owner/User Discovery
Discovery
T1046
Network Service Discovery
Discovery
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Exfiltration
T1053
Scheduled Task/Job
Execution
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1055.003
Thread Execution Hijacking
Defense Evasion
T1057
Process Discovery
Discovery
T1059.001
PowerShell
Execution
T1070.001
Clear Windows Event Logs
Defense Evasion
T1070.004
File Deletion
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1071.003
Mail Protocols
Command And Control
T1074
Data Staged
Collection
T1074.001
Local Data Staging
Collection
T1078
Valid Accounts
Defense Evasion
T1078.001
Default Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1086
T1086
T1087.001
Local Account
Discovery
T1087.002
Domain Account
Discovery
T1090.001
Internal Proxy
Command And Control
T1090.003
Multi-hop Proxy
Command And Control
T1098
Account Manipulation
Persistence
T1098.001
Additional Cloud Credentials
Persistence
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1110.003
Password Spraying
Credential Access
T1112
Modify Registry
Defense Evasion
T1114
Email Collection
Collection
T1129
Shared Modules
Execution
T1133
External Remote Services
Persistence
T1140
Deobfuscate/Decode Files or Information
Defense Evasion
T1204.002
Malicious File
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1212
Exploitation for Credential Access
Credential Access
T1222
File and Directory Permissions Modification
Defense Evasion
T1222.001
Windows File and Directory Permissions Modification
Defense Evasion
T1482
Domain Trust Discovery
Discovery
T1484
Domain or Tenant Policy Modification
Defense Evasion
T1484.001
Group Policy Modification
Defense Evasion
T1485
Data Destruction
Impact
T1486
Data Encrypted for Impact
Impact
T1489
Service Stop
Impact
T1490
Inhibit System Recovery
Impact
T1537
Transfer Data to Cloud Account
Exfiltration
T1543.003
Windows Service
Persistence
T1547.001
Registry Run Keys / Startup Folder
Persistence
T1558.003
Kerberoasting
Credential Access
T1562.001
Disable or Modify Tools
Defense Evasion
T1566
Phishing
Initial Access
T1569.002
Service Execution
Execution
T1570
Lateral Tool Transfer
Lateral Movement
T1571
Non-Standard Port
Command And Control
T1572
Protocol Tunneling
Command And Control
T1573
Encrypted Channel
Command And Control
T1573.001
Symmetric Cryptography
Command And Control
T1574
Hijack Execution Flow
Persistence
T1589
Gather Victim Identity Information
Reconnaissance
T1614
System Location Discovery
Discovery

Source Articles

Trigona Affiliates Deploy Custom Exfiltration Tool to Streamline Data Theft
Trigona ransomware affiliates have deployed a custom exfiltration tool, uploader_client.exe, in attacks observed in March 2026, marking a shift from using common tools like Rclone to proprietary malware for greater control and stealth. The custom tool enables parallel data streams, connection rotation to evade detection, granular file filtering, and uses a shared key for authentication with the attacker-controlled server. Prior to data exfiltration, attackers disable security software using kernel-level tools such as HRSword, PCHunter, Gmer, and others, often leveraging vulnerable drivers (BYOVD technique), and gain remote access via AnyDesk. Credential theft is conducted using Mimikatz and Nirsoft tools.
security-com ·4mo ago
GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses
The GodDamn ransomware, a rebranded variant of Beast and Monster ransomware, has been used in a recent attack attributed to the threat actor Hyadina. The attackers leveraged AnyDesk for remote access, deployed the malicious PoisonX kernel driver—signed by Microsoft—to disable endpoint defenses, and used a suite of credential-harvesting tools from NirSoft. The attack involved lateral movement via PsExec, deployment of backdoors across multiple hosts, and eventual execution of the ransomware payload after a four-day dwell period. This represents an evolution in defensive evasion tactics, leveraging signed malicious drivers in a BYOVD-style attack.
security-com ·1mo ago
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
The GoSerpent campaign is a sophisticated and evolving threat targeting government and diplomatic entities in Southeast Asia since at least 2021, with ongoing activity observed through 2026. The primary malware, GoSerpent, is a Go-based backdoor that enables remote access, SOCKS5 proxying, and deployment of additional tools for data collection and credential dumping. In 2026, attackers expanded their toolkit with Stowaway, a new Go-based RAT, and TmcLoader/TmcPayload, a stealthy two-stage payload used for exfiltrating data collected by earlier stages. The attack chain demonstrates high operational integration, using credential dumping tools like Mimikatz and QuarksDumpLocalHash to enable lateral movement and exfiltration of archived sensitive files via network shares.
securelist ·1mo ago
Uncovering Qilin attack methods exposed through multiple cases
The Qilin ransomware group, active since 2022 and operating as a Ransomware-as-a-Service (RaaS), has intensified its global operations in 2025, targeting primarily the manufacturing, professional services, and wholesale trade sectors. The group employs a double-extortion strategy, combining file encryption with data exfiltration, leveraging tools such as Mimikatz, Cyberduck, and Cobalt Strike. Initial access is suspected via compromised credentials on exposed VPNs without MFA, followed by extensive reconnaissance, credential dumping, lateral movement, and deployment of dual encryptors to maximize impact.
talos
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
A previously undocumented malware named GoSerpent has been used in cyber espionage campaigns targeting government and diplomatic entities in Southeast Asia since late 2025. The malware enables long-term access, credential dumping, and data exfiltration through a suite of tools including Mimikatz, QuarksDumpLocalHash, and a custom file collection tool called ThumbcacheService. In May 2026, attackers returned to compromised environments to deploy evolved tools such as Stowaway and TmcLoader/TmcPayload for further data exfiltration. The activity shows operational overlaps with the TetrisPhantom threat actor, though definitive attribution remains unconfirmed.
hacker-news ·1mo ago
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
CL-STA-1062, a Chinese-speaking threat actor group active since at least March 2022, has been targeting government entities and critical infrastructure in Southeast Asia. The group, also tracked as UAT-7237, uses a hybrid toolkit combining open-source tools like SoftEther VPN, Mimikatz, and VNT with a custom backdoor named TinyRCT. This backdoor enables command execution, file exfiltration, screen capture, and self-destruction, and is deployed via AppDomainManager injection through a maliciously crafted archive. The campaign demonstrates a sustained regional focus, with attacks spanning from Taiwan to Southeast Asia, particularly targeting energy and government sectors.
unit42 ·2mo ago