Responder

MITRE ATT&CK: S0174 View on attack.mitre.org

Aliases: SpiderLabs Responder, Responder

Malware type
credential-stealer
Family
Malware family
Related IoCs
242 (3 malicious)
Last IoC activity
2026-09-01 18:24:22
Profile updated
2026-07-07 14:29:19

Context

Responder is an open source tool used for LLMNR, NBT-NS and MDNS poisoning, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to Responder (S0174). The 2 most recently updated:

TypeIndicatorUpdatedSources
IP address 91.193.18.110 2026-08-22 7
IP address 159.223.178.234 2026-08-14 3

Detection coverage

  • 19 Sigma rules

Malware & tools used

  • Network Sniffing (attack-pattern)
  • Name Resolution Poisoning and SMB Relay (attack-pattern)

Used by threat actors

Reports & references

  • yoroi.company — Shadows From The Past Threaten Italian Enterprises (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Responder (report)
  • github.com — Responder (report)
  • MITRE ATT&CK — S0174 (report)
  • github.com — Responder (report)

External references