ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Mimikatz

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Mimikatz

NamesMimikatz
CategoryTools
TypeCredential stealer, Keylogger
Description(SANS) Mimikatz provides a wealth of tools for collecting and making use of Windows credentials on target systems, including retrieval of cleartext passwords, Lan Manager hashes, and NTLM hashes, certificates, and Kerberos tickets. The tools run with varying success on all versions of Windows from XP forward, with functionality somewhat limited in Windows 8.1 and later.
Information<https://github.com/gentilkiwi/mimikatz>
<https://www.sans.org/reading-room/whitepapers/intrusion/mimikatz-overview-defenses-detection-36780>
<https://www.wired.com/story/how-mimikatz-became-go-to-hacker-tool/>
<https://www.crowdstrike.com/blog/credential-theft-mimikatz-techniques/>
MITRE ATT&CK<https://attack.mitre.org/software/S0002/>
Malpedia<https://malpedia.caad.fkie.fraunhofer.de/details/win.mimikatz>
AlienVault OTX<https://otx.alienvault.com/browse/pulses?q=tag:mimikatz>

Last change to this tool card: 14 May 2020

Download this tool card in JSON format

Previous: Milum
Next: MINEBRIDGE

All groups using tool Mimikatz

ChangedNameCountryObserved

APT groups

 APT 20, Violin PandaChina2014-2017 
 APT 29, Cozy Bear, The DukesRussia2008-2020X
XAPT 32, OceanLotus, SeaLotusVietnam2013-Dec 2020 HOTX
XAPT 33, Elfin, MagnalliumIran2013-Nov 2019 
XAPT 41China2012-Aug 2020X
 AVIVOREChina2015 
XBronze Butler, Tick, RedBaldNight, Stalker PandaChina2010-Jun 2019 
 CalypsoChina2016 
 Carbanak, AnunakUkraine2013-Aug 2018X
XChafer, APT 39Iran2014-Sep 2020X
 Cobalt GroupRussia2016-Oct 2019X
 Comment Crew, APT 1China2006-May 2018X
 DarkHydrus, LazyMeerkatIran2016-Jan 2019 
XEmissary Panda, APT 27, LuckyMouse, Bronze UnionChina2010-Jun 2020 
XFIN6, Skeleton Spider[Unknown]2015-Mar 2020 
XFIN7Russia2013-Dec 2020 HOTX
 GalliumChina2018 
 Hurricane PandaChina2013-Mar 2014 
 IAmTheKingRussia2018 
XKe3chang, Vixen Panda, APT 15, GREF, Playful DragonChina2010-May 2020 
XKimsuky, Velvet ChollimaNorth Korea2012-Mar 2020X
XLazarus Group, Hidden Cobra, Labyrinth ChollimaNorth Korea2007-Dec 2020 HOTX
 Leafminer, RaspiteIran2017 
XLotus Blossom, Spring Dragon, ThripChina2012-Jun 2018 
 Magic Hound, APT 35, Cobalt Gypsy, Charming KittenIran2013-Jul 2020X
 MikroceenChina2017 
XMuddyWater, Seedworm, TEMP.Zagros, Static KittenIran2017-Dec 2020 HOTX
XOilRig, APT 34, Helix Kitten, ChryseneIran2014-Apr 2020X
 Operation DRBControlChina2019 
XOperation SignSight[Unknown]2020 
 PittyTiger, Pitty PandaChina2011-2014 
XSofacy, APT 28, Fancy Bear, SednitRussia2004-Nov 2020 HOTX
XStone Panda, APT 10, menuPassChina2006-Jul 2020X
XTA2101, Maze Team[Unknown]2019-Oct 2020 HOT 
 TaskMastersChina2010 
 TEMP.VelesRussia2014-Feb 2019 
XTonto Team, HartBeat, Karma PandaChina2009-Dec 2019 
XTurla, Waterbug, Venomous BearRussia1996-Jun 2020 
XUNC2452, Dark Halo, SolarStormRussia2019 
 WassoniteNorth Korea2018-Oct 2019 
 Whitefly, Mofang[Unknown]2012-Jul 2018 

Other groups

XBoss Spider, Gold LowellIran2015-Nov 2018X
XIndrik SpiderRussia2014-Jul 2020X
 Parinacota[Unknown]2018 

44 groups listed (41 APT, 3 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key