Impacket
MITRE ATT&CK: S0357 View on attack.mitre.org
Aliases: Impacket
- First seen
- 2012-05-15 00:00:00
- Malware type
- credential-stealer, exploit-kit, spyware
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Profile updated
- 2026-07-07 15:33:13
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services professional-services
Context
Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.
Detection coverage
- 1 YARA rules
- 260 Sigma rules
Malware & tools used
- Name Resolution Poisoning and SMB Relay (attack-pattern)
- Network Sniffing (attack-pattern)
- Kerberoasting (attack-pattern)
- Ccache Files (attack-pattern)
- NTDS (attack-pattern)
- Service Execution (attack-pattern)
- LSASS Memory (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Security Account Manager (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- LSA Secrets (attack-pattern)
Used by threat actors
- HomeLand Justice (campaign)
- C0027 (campaign)
- SharePoint ToolShell Exploitation (campaign)
- Operation Wocao (campaign)
- 2025 Poland Wiper Attacks (campaign)
- Cutting Edge (campaign)
- May 2023 Exfiltration & Wiper Activity (Truebot + FlawedGrace + MBR Killer) (campaign)
- Sandworm Team (threat-actor)
- Magic Hound (threat-actor)
- Cinnamon Tempest (threat-actor)
- Volt Typhoon (threat-actor)
- Mustang Panda (threat-actor)
- Dragonfly (threat-actor)
- menuPass (threat-actor)
- FIN13 (threat-actor)
- HAFNIUM (threat-actor)
- APT29 (threat-actor)
- APT41 (threat-actor)
- FIN8 (threat-actor)
- Ember Bear (threat-actor)
- Velvet Ant (threat-actor)
- Storm-0501 (threat-actor)
- Storm-1811 (threat-actor)
- Threat Group-3390 (threat-actor)
- Lotus Blossom (threat-actor)
Detection rules
- SEKOIA_Hacktool_Impacket_Compiled_Binary (yara-rule)
Reports & references
- MITRE ATT&CK — S0357 (report)
- secureauth.com — Impacket (report)