Mimikatz

MITRE ATT&CK: S0002 View on attack.mitre.org

Aliases: Mimikatz

First seen
2011-05-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
2778 (2411 malicious)
Last IoC activity
2026-09-02 01:56:44
Profile updated
2026-07-07 12:35:20

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical energy-and-utilities technology-and-telecommunications

Context

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks.

Recent IoC activity

2,412 malicious indicators in Maltiverse are attributed to Mimikatz (S0002). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname v2202501250277308833.bestsrv.de 2026-09-03 1
hostname yunshang.click 2026-09-02 1
URL https://github.com/Zusyaku/Malware-Collection-Part-2/blob/main/NotPetya.exe 2026-09-02 1
file sample 2026-09-01_94a4c614e0f8a50957673cf6b8342450_fabookie_glassworm_hacktools_mimikatz 2026-09-02 1
hostname ip212-227-245-12.pbiaas.com 2026-09-02 2
file sample 2026-05-23_1c91edcaf84b425bd00f0a78873ec823_coinminer_elex_glassworm_hacktool... 2026-09-02 1
file sample 768fe2181e2f8595d84ccd19ea882ebb6632482ee4ad4954637289a278d27a85 2026-09-02 3
file sample 2026-04-02_5b32e3e219b94f502aa9f2db76ec6564_cobalt-strike_glassworm_hacktools... 2026-09-02 1
hostname crm.immunlt.ch 2026-09-02 1
hostname 51.15.59.34.bc.googleusercontent.com 2026-09-02 1
hostname crestwaybunk.netlify.app 2026-09-02 2
hostname 156.65.16.34.bc.googleusercontent.com 2026-09-02 1
file sample 2026-08-31_f42fef64cd2e89f5f8dfecc226c6cfe5_fabookie_glassworm_hacktools_mimi... 2026-09-01 1
file sample 2026-08-31_fe684f4c9d820a4b998f6c66fde5ee62_amadey_cloudeye_coinminer_dragonf... 2026-09-01 1
file sample 6dcb8ef81ffb990d544d6ecd9b6339ed96f0697359cc25c866ae0e5d9dafa639 2026-09-01 3
file sample 2026-09-01_c79deccc3b08c65103a0fc53206668c7_amadey_cloudeye_coinminer_dragonf... 2026-09-01 1
file sample 2026-08-30_0a34d5aadd55f476a6883deb5dea40c0_amadey_cloudeye_coinminer_dragonf... 2026-09-01 1
file sample 2026-08-30_0b0a2f10ccb1b56d6cc631f570c8ab9c_amadey_cloudeye_coinminer_dragonf... 2026-09-01 1
URL http://falconsplayingpoker.com/allyourbase/Falconkatz.ps1 2026-09-01 1
hostname falconsplayingpoker.com 2026-09-01 1

Detection coverage

  • 7 YARA rules
  • 193 Sigma rules

Malware & tools used

  • Credentials from Password Stores (attack-pattern)
  • Rogue Domain Controller (attack-pattern)
  • Private Keys (attack-pattern)
  • SID-History Injection (attack-pattern)
  • Security Support Provider (attack-pattern)
  • Pass the Hash (attack-pattern)
  • Account Manipulation (attack-pattern)
  • Pass the Ticket (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Golden Ticket (attack-pattern)
  • Security Account Manager (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Silver Ticket (attack-pattern)
  • Windows Credential Manager (attack-pattern)
  • Steal or Forge Authentication Certificates (attack-pattern)
  • LSA Secrets (attack-pattern)
  • DCSync (attack-pattern)

Used by threat actors

Exploited vulnerabilities

  • CVE-2022-42475 (vulnerability)
  • CVE-2022-47966 (vulnerability)

Detection rules

  • SBOUSSEADEN_Mimikatz_Memssp_Hookfn (yara-rule)
  • SBOUSSEADEN_Mimikatz_Kiwikey (yara-rule)
  • SEKOIA_Hacktool_Mimikatz_Obfuscated (yara-rule)
  • SIGNATURE_BASE_Mimikatz (yara-rule)
  • SIGNATURE_BASE_HKTL_Mimikatz_Skeletonkey_In_Memory_Aug20_1 (yara-rule)
  • SIGNATURE_BASE_HKTL_Mimikatz_Memssp_Hookfn (yara-rule)
  • MALPEDIA_Win_Mimikatz_Auto (yara-rule)

Reports & references

  • Broadcom/Symantec — Grayling Taiwan Cyber Attacks (report)
  • ESET — Exchange Servers Under Siege 10 Apt Groups (report)
  • Broadcom/Symantec — Cicada Apt10 China Ngo Government Attacks (report)
  • MITRE ATT&CK — G0011 (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • Broadcom/Symantec — Viewdocument (report)
  • MITRE ATT&CK — G0034 (report)
  • hvs-consulting.de — Lazarus Report (report)
  • secureworks.com — Gold Franklin (report)
  • secureworks.com — Tin Woodlawn (report)
  • Broadcom/Symantec — Leafminer Espionage Middle East (report)
  • secureworks.com — Gold Kingswood (report)
  • Palo Alto Unit 42 — Obscureserpens (report)
  • secureworks.com — Cobalt Hickman (report)
  • secureworks.com — Ransomware Deployed By Adversary (report)
  • secureworks.com — Samsam Ransomware Campaigns (report)
  • secureworks.com — Bronze Vinewood Targets Supply Chains (report)
  • secureworks.com — Bronze Vinewood (report)
  • secureworks.com — Bronze Atlas (report)
  • MITRE ATT&CK — G0096 (report)
  • cybereason.com — Operation Soft Cell A Worldwide Campaign Against Telecommunications Providers (report)
  • Microsoft — Gallium Targeting Global Telecom (report)
  • zdnet.com — Fbi Says An Iranian Hacking Group Is Attacking F5 Networking Devices (report)
  • secureworks.com — Gold Drake (report)
  • i.blackhat.com — Us 20 Chen Operation Chimera Apt Operation Targets Semiconductor Vendors (report)

External references