ATT&CKReferencesHuntress NPPSPY 2022

Huntress NPPSPY 2022

Dray Agha. (2022, August 16). Cleartext Shenanigans: Gifting User Passwords to Adversaries With NPPSPY. Retrieved May 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1005
Data from Local System
ToolNPPSPY

NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext.

T1056
Input Capture
ToolNPPSPY

NPPSPY captures user input into the Winlogon process by redirecting RPC traffic from legitimate listening DLLs within the operating system to a newly registered malicious item that allows for recording logon information in cleartext.

T1112
Modify Registry
ToolNPPSPY

NPPSPY modifies the Registry to record the malicious listener for output from the Winlogon process.

T1119
Automated Collection
ToolNPPSPY

NPPSPY collection is automatically recorded to a specified file on the victim machine.

T1552
Unsecured Credentials
ToolNPPSPY

NPPSPY captures credentials by recording them through an alternative network listener registered to the mpnotify.exe process, allowing for cleartext recording of logon information.

T1557
Adversary-in-the-Middle
ToolNPPSPY

NPPSPY opens a new network listener for the mpnotify.exe process that is typically contacted by the Winlogon process in Windows. A new, alternative RPC channel is set up with a malicious DLL recording plaintext credentials entered into Winlogon, effectively intercepting and redirecting the logon information.

T1684.001
Impersonation
ToolNPPSPY

NPPSPY creates a network listener using the misspelled label logincontroll recorded to the Registry key HKLM\\SYSTEM\\CurrentControlSet\\Control\\NetworkProvider\\Order.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.