pwdump

MITRE ATT&CK: S0006 View on attack.mitre.org

Aliases: pwdump

Malware type
credential-stealer
Operating systems
windows
Related IoCs
3 (3 malicious)
Last IoC activity
2025-10-28 22:30:38
Profile updated
2026-07-07 15:32:10

Context

pwdump is a credential dumper designed to extract password hashes from Windows systems. It is commonly used in post-exploitation scenarios to obtain user credentials.

Recent IoC activity

3 malicious indicators in Maltiverse are attributed to pwdump (S0006). The 3 most recently updated:

TypeIndicatorUpdatedSources
file sample lkwgbwlr.dll 2025-10-28 1
file sample tmprles7nk2 2025-10-15 1
file sample tmpyx_mdevg 2025-10-10 1

Detection coverage

  • 28 Sigma rules

Malware & tools used

  • Security Account Manager (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0006 (report)
  • Wikipedia — Pwdump (report)

External references