gsecdump
MITRE ATT&CK: S0008 View on attack.mitre.org
Aliases: gsecdump
- Malware type
- credential-stealer
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:45:34
Context
gsecdump is a publicly-available credential dumper used to obtain password hashes and LSA secrets from Windows operating systems.
Detection coverage
- 1 YARA rules
- 40 Sigma rules
Malware & tools used
- Security Account Manager (attack-pattern)
- LSA Secrets (attack-pattern)
Used by threat actors
- Night Dragon (campaign)
- Threat Group-3390 (threat-actor)
- BRONZE BUTLER (threat-actor)
- Tonto Team (threat-actor)
- APT1 (threat-actor)
- PittyTiger (threat-actor)
Detection rules
- MALPEDIA_Win_Gsecdump_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Gsecdump (report)
- MITRE ATT&CK — T1003 (report)
- MITRE ATT&CK — S0008 (report)
- web.archive.org — Gsecdump V2.0B5 (report)