Fgdump

MITRE ATT&CK: S0120 View on attack.mitre.org

Aliases: Fgdump

First seen
2007-06-01 00:00:00
Malware type
credential-stealer
Family
Malware family
Operating systems
windows
Last IoC activity
2026-06-15 10:45:04
Profile updated
2026-07-07 12:34:53

Context

Fgdump is a tool specifically designed to dump Windows password hashes, often used by attackers to crack or abuse credentials. It is commonly employed in post-exploitation scenarios.

Detection coverage

  • 1 YARA rules
  • 28 Sigma rules

Malware & tools used

  • Security Account Manager (attack-pattern)

Detection rules

  • DITEKSHEN_INDICATOR_TOOL_PWS_Fgdump (yara-rule)

Reports & references

  • Mandiant — Mandiant Apt1 Report (report)
  • MITRE ATT&CK — S0120 (report)

External references