Mimikatz
MITRE ATT&CK: S0002 View on attack.mitre.org
Aliases: Mimikatz
- First seen
- 2011-05-01 00:00:00
- Malware type
- credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 2778 (2411 malicious)
- Last IoC activity
- 2026-09-02 01:56:44
- Profile updated
- 2026-07-07 12:35:20
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical energy-and-utilities technology-and-telecommunications
Context
Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks.
Recent IoC activity
2,412 malicious indicators in Maltiverse are attributed to Mimikatz (S0002). The 20 most recently updated:
Detection coverage
- 7 YARA rules
- 193 Sigma rules
Malware & tools used
- Credentials from Password Stores (attack-pattern)
- Rogue Domain Controller (attack-pattern)
- Private Keys (attack-pattern)
- SID-History Injection (attack-pattern)
- Security Support Provider (attack-pattern)
- Pass the Hash (attack-pattern)
- Account Manipulation (attack-pattern)
- Pass the Ticket (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Golden Ticket (attack-pattern)
- Security Account Manager (attack-pattern)
- LSASS Memory (attack-pattern)
- Silver Ticket (attack-pattern)
- Windows Credential Manager (attack-pattern)
- Steal or Forge Authentication Certificates (attack-pattern)
- LSA Secrets (attack-pattern)
- DCSync (attack-pattern)
Used by threat actors
- Operation Wocao (campaign)
- Operation Digital Eye (campaign)
- SharePoint ToolShell Exploitation (campaign)
- HomeLand Justice (campaign)
- C0032 (campaign)
- C0018 (campaign)
- SolarWinds Compromise (campaign)
- C0017 (campaign)
- Triton Safety Instrumented System Attack (campaign)
- GOLD BURLAP (threat-actor)
- Karakurt (threat-actor)
- Threat Group-3390 (threat-actor)
- BRONZE BUTLER (threat-actor)
- Cobalt Group (threat-actor)
- Wizard Spider (threat-actor)
- Earth Lusca (threat-actor)
- Blue Mockingbird (threat-actor)
- Sandworm Team (threat-actor)
- Magic Hound (threat-actor)
- Tonto Team (threat-actor)
- Medusa Group (threat-actor)
- Scattered Spider (threat-actor)
- Volt Typhoon (threat-actor)
- Indrik Spider (threat-actor)
- Mustang Panda (threat-actor)
Exploited vulnerabilities
- CVE-2022-42475 (vulnerability)
- CVE-2022-47966 (vulnerability)
Detection rules
- SBOUSSEADEN_Mimikatz_Memssp_Hookfn (yara-rule)
- SBOUSSEADEN_Mimikatz_Kiwikey (yara-rule)
- SEKOIA_Hacktool_Mimikatz_Obfuscated (yara-rule)
- SIGNATURE_BASE_Mimikatz (yara-rule)
- SIGNATURE_BASE_HKTL_Mimikatz_Skeletonkey_In_Memory_Aug20_1 (yara-rule)
- SIGNATURE_BASE_HKTL_Mimikatz_Memssp_Hookfn (yara-rule)
- MALPEDIA_Win_Mimikatz_Auto (yara-rule)
Reports & references
- Broadcom/Symantec — Grayling Taiwan Cyber Attacks (report)
- ESET — Exchange Servers Under Siege 10 Apt Groups (report)
- Broadcom/Symantec — Cicada Apt10 China Ngo Government Attacks (report)
- MITRE ATT&CK — G0011 (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- Broadcom/Symantec — Viewdocument (report)
- MITRE ATT&CK — G0034 (report)
- hvs-consulting.de — Lazarus Report (report)
- secureworks.com — Gold Franklin (report)
- secureworks.com — Tin Woodlawn (report)
- Broadcom/Symantec — Leafminer Espionage Middle East (report)
- secureworks.com — Gold Kingswood (report)
- Palo Alto Unit 42 — Obscureserpens (report)
- secureworks.com — Cobalt Hickman (report)
- secureworks.com — Ransomware Deployed By Adversary (report)
- secureworks.com — Samsam Ransomware Campaigns (report)
- secureworks.com — Bronze Vinewood Targets Supply Chains (report)
- secureworks.com — Bronze Vinewood (report)
- secureworks.com — Bronze Atlas (report)
- MITRE ATT&CK — G0096 (report)
- cybereason.com — Operation Soft Cell A Worldwide Campaign Against Telecommunications Providers (report)
- Microsoft — Gallium Targeting Global Telecom (report)
- zdnet.com — Fbi Says An Iranian Hacking Group Is Attacking F5 Networking Devices (report)
- secureworks.com — Gold Drake (report)
- i.blackhat.com — Us 20 Chen Operation Chimera Apt Operation Targets Semiconductor Vendors (report)