Pass the Hash

T1550.002

Sub-technique of T1550 Use Alternate Authentication Material.View on attack.mitre.org

About this technique

Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls. Pass the hash (PtH) is a method of authenticating as a user without having access to the user's cleartext password. This method bypasses standard authentication steps that require a cleartext password, moving directly into the portion of the authentication that uses the password hash.

When performing PtH, valid password hashes for the account being used are captured using a Credential Access technique. Captured hashes are used with PtH to authenticate as that user. Once authenticated, PtH may be used to perform actions on local or remote systems.

Adversaries may also use stolen password hashes to "overpass the hash." Similar to PtH, this involves using a password hash to authenticate as a user but also uses the password hash to create a valid Kerberos ticket. This ticket can then be used to perform Pass the Ticket attacks.

Detection rules6

Rules on DetectionCode tagged with T1550.002.

Sigma5

RuleLevelLog source
Hacktool Rulerhighwindows / NULL
Successful Overpass the Hash Attempthighwindows / NULL
NTLMv1 Logon Between Client and Servermediumwindows / NULL
Pass the Hash Activity 2mediumwindows / NULL
NTLM Logonlowwindows / NULL

Splunk1

RuleTypeRiskData source
Detect Activity Related to Pass the Hash AttacksHuntingNULLWindows Event Log Security 4624

Groups11

Software8

Campaigns3

Procedure examples22

Groups11

Used byProcedure example
GroupAPT1

The APT1 group is known to have used pass the hash.

GroupAPT28

APT28 has used pass the hash for lateral movement.

GroupAPT32

APT32 has used pass the hash for lateral movement.

GroupAPT41

APT41 uses tools such as Mimikatz to enable lateral movement via captured password hashes.

GroupAquatic Panda

Aquatic Panda used a registry edit to enable a Windows feature called RestrictedAdmin in victim environments. This change allowed Aquatic Panda to leverage "pass the hash" mechanisms as the alteration allows for RDP connections with a valid account name and hash only, without possessing a cleartext password value.

GroupChimera

Chimera has dumped password hashes for use in pass the hash authentication attacks.

GroupEmber Bear

Ember Bear has used pass-the-hash techniques for lateral movement in victim environments.

GroupFIN13

FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment.

View all 11 groups examples

Software8

Used byProcedure example
MalwareBADHATCH

BADHATCH can perform pass the hash on compromised machines with x64 versions.

MalwareCobalt Strike

Cobalt Strike can perform pass the hash.

ToolCrackMapExec

CrackMapExec can pass the hash to authenticate via SMB.

ToolEmpire

Empire can perform pass the hash attacks.

MalwareHOPLIGHT

HOPLIGHT has been observed loading several APIs associated with Pass the Hash.

ToolMimikatz

Mimikatz's SEKURLSA::Pth module can impersonate a user, with only a password hash, to execute arbitrary commands.

ToolPass-The-Hash Toolkit

Pass-The-Hash Toolkit can perform pass the hash.

ToolPoshC2

PoshC2 has a number of modules that leverage pass the hash for lateral movement.

Campaigns3

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries attempted to reuse password hash values to gain access to other systems.

CampaignNight Dragon

During Night Dragon, threat actors used pass-the-hash tools to obtain authenticated access to sensitive internal desktops and servers.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used a pass-the-hash capability to move laterally.

References1

  1. Stealthbits Overpass-the-Hash Open source
    Warren, J. (2019, February 26). How to Detect Overpass-the-Hash Attacks. Retrieved February 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.