ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1003.001×

44 examples

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupIndrik Spider

Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump.

T1003.001
LSASS Memory
GroupGALLIUM

GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines.

T1003.001
LSASS Memory
GroupAPT3

APT3 has used a tool to dump credentials by injecting itself into lsass.exe and triggering with the argument "dig."

T1003.001
LSASS Memory
GroupKimsuky

Kimsuky has gathered credentials using Mimikatz and ProcDump.

T1003.001
LSASS Memory
GroupVolt Typhoon

Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space.

T1003.001
LSASS Memory
GroupAPT41

APT41 has used hashdump, Mimikatz, Procdump, and the Windows Credential Editor to dump password hashes from memory and authenticate to other user accounts.

T1003.001
LSASS Memory
GroupAPT32

APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials.

T1003.001
LSASS Memory
GroupHAFNIUM

HAFNIUM has used procdump to dump the LSASS process memory.

T1003.001
LSASS Memory
GroupMuddyWater

MuddyWater has performed credential dumping with Mimikatz and procdump64.exe.

T1003.001
LSASS Memory
GroupFIN6

FIN6 has used Windows Credential Editor for credential dumping.

T1003.001
LSASS Memory
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne and Mimikatz.

T1003.001
LSASS Memory
GroupSandworm Team

Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory.

T1003.001
LSASS Memory
GroupMustang Panda

Mustang Panda has harvested credentials from memory of lssas.exe with Mimikatz.

T1003.001
LSASS Memory
GroupAPT39

APT39 has used Mimikatz, Windows Credential Editor and ProcDump to dump credentials.

T1003.001
LSASS Memory
GroupUNC3886

UNC3886 has used MiniDump to dump process memory and search for cleartext credentials.

T1003.001
LSASS Memory
GroupOilRig

OilRig has used credential dumping tools such as Mimikatz to steal credentials to accounts logged into the compromised system and to Outlook Web Access.

T1003.001
LSASS Memory
GroupAquatic Panda

Aquatic Panda has attempted to harvest credentials through LSASS memory dumping.

T1003.001
LSASS Memory
GroupKe3chang

Ke3chang has dumped credentials, including by using Mimikatz.

T1003.001
LSASS Memory
GroupAPT1

APT1 has been known to use credential dumping using Mimikatz.

T1003.001
LSASS Memory
GroupLeviathan

Leviathan has used publicly available tools to dump password hashes, including ProcDump and WCE.

T1003.001
LSASS Memory
GroupBlue Mockingbird

Blue Mockingbird has used Mimikatz to retrieve credentials from LSASS memory.

T1003.001
LSASS Memory
GroupRedCurl

RedCurl used LaZagne to obtain passwords from memory.

T1003.001
LSASS Memory
GroupMirrorFace

MirrorFace has dumped LSASS memory for credential access.

T1003.001
LSASS Memory
GroupCleaver

Cleaver has been known to dump credentials using Mimikatz and Windows Credential Editor.

T1003.001
LSASS Memory
GroupMedusa Group

Medusa Group has leveraged Mimikatz to dump LSASS to harvest credentials.

T1003.001
LSASS Memory
GroupBRONZE BUTLER

BRONZE BUTLER has used various tools (such as Mimikatz and WCE) to perform credential dumping.

T1003.001
LSASS Memory
GroupEmber Bear

Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory.

T1003.001
LSASS Memory
GroupWhitefly

Whitefly has used Mimikatz to obtain credentials.

T1003.001
LSASS Memory
GroupAgrius

Agrius used tools such as Mimikatz to dump LSASS memory to capture credentials in victim environments.

T1003.001
LSASS Memory
GroupAPT28

APT28 regularly deploys both publicly available (ex: Mimikatz) and custom password retrieval tools on victims. They have also dumped the LSASS process memory using the MiniDump function.

T1003.001
LSASS Memory
GroupAPT5

APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive.

T1003.001
LSASS Memory
GroupFox Kitten

Fox Kitten has used prodump to dump credentials from LSASS.

T1003.001
LSASS Memory
GroupEarth Lusca

Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process.

T1003.001
LSASS Memory
GroupSilence

Silence has used the Farse6.1 utility (based on Mimikatz) to extract credentials from lsass.exe.

T1003.001
LSASS Memory
GroupWizard Spider

Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne.

T1003.001
LSASS Memory
GroupMoonstone Sleet

Moonstone Sleet retrieved credentials from LSASS memory.

T1003.001
LSASS Memory
GroupVOID MANTICORE

VOID MANTICORE has dumped LSASS credentials using `comsvcs.dll` via `rundll32.exe`.

T1003.001
LSASS Memory
GroupPlay

Play has used Mimikatz and the Windows Task Manager to dump LSASS process memory.

T1003.001
LSASS Memory
GroupPLATINUM

PLATINUM has used keyloggers that are also capable of dumping credentials.

T1003.001
LSASS Memory
GroupMagic Hound

Magic Hound has stolen domain credentials by dumping LSASS process memory using Task Manager, comsvcs.dll, and from a Microsoft Active Directory Domain Controller using Mimikatz.

T1003.001
LSASS Memory
GroupThreat Group-3390

Threat Group-3390 actors have used a modified version of Mimikatz called Wrapikatz to dump credentials. They have also dumped credentials from domain controllers.

T1003.001
LSASS Memory
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne, Mimikatz, and ProcDump to dump credentials.

T1003.001
LSASS Memory
GroupFIN8

FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE).

T1003.001
LSASS Memory
GroupFIN13

FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.