pwdump
MITRE ATT&CK: S0006 View on attack.mitre.org
Aliases: pwdump
- Malware type
- credential-stealer
- Operating systems
- windows
- Related IoCs
- 3 (3 malicious)
- Last IoC activity
- 2025-10-28 22:30:38
- Profile updated
- 2026-07-07 15:32:10
Context
pwdump is a credential dumper designed to extract password hashes from Windows systems. It is commonly used in post-exploitation scenarios to obtain user credentials.
Recent IoC activity
3 malicious indicators in Maltiverse are attributed to pwdump (S0006). The 3 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | lkwgbwlr.dll | 2025-10-28 | 1 |
| file sample | tmprles7nk2 | 2025-10-15 | 1 |
| file sample | tmpyx_mdevg | 2025-10-10 | 1 |
Detection coverage
- 28 Sigma rules
Malware & tools used
- Security Account Manager (attack-pattern)
Used by threat actors
Reports & references
- MITRE ATT&CK — S0006 (report)
- Wikipedia — Pwdump (report)