Responder
MITRE ATT&CK: S0174 View on attack.mitre.org
Aliases: SpiderLabs Responder, Responder
- Malware type
- credential-stealer
- Family
- Malware family
- Related IoCs
- 242 (3 malicious)
- Last IoC activity
- 2026-09-01 18:24:22
- Profile updated
- 2026-07-07 14:29:19
Context
Responder is an open source tool used for LLMNR, NBT-NS and MDNS poisoning, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to Responder (S0174). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 91.193.18.110 | 2026-08-22 | 7 |
| IP address | 159.223.178.234 | 2026-08-14 | 3 |
Detection coverage
- 19 Sigma rules
Malware & tools used
- Network Sniffing (attack-pattern)
- Name Resolution Poisoning and SMB Relay (attack-pattern)
Used by threat actors
- Operation Dream Job (campaign)
- Ember Bear (threat-actor)
- Lazarus Group (threat-actor)
- APT28 (threat-actor)
Reports & references
- yoroi.company — Shadows From The Past Threaten Italian Enterprises (report)
- malpedia.caad.fkie.fraunhofer.de — Py.Responder (report)
- github.com — Responder (report)
- MITRE ATT&CK — S0174 (report)
- github.com — Responder (report)