Skeleton Key

MITRE ATT&CK: S0007 View on attack.mitre.org

Aliases: Skeleton Key

First seen
2014-01-01 00:00:00
Malware type
backdoor, credential-stealer
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:28:05

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical

Context

Skeleton Key is malware used to inject false credentials into domain controllers with the intent of creating a backdoor password. Functionality similar to Skeleton Key is included as a module in Mimikatz.

Malware & tools used

  • Domain Controller Authentication (attack-pattern)

Used by threat actors

  • APT5 (threat-actor)

Reports & references

  • MITRE ATT&CK — S0007 (report)
  • secureworks.com — Skeleton Key Malware Analysis (report)

External references