logo

Unravelling a Mimikatz campaign

ID: a0d73e2a-37d9-5c82-ba33-522ad90a09d1

STIX ID: report--a0d73e2a-37d9-5c82-ba33-522ad90a09d1

Feed Name: BushidoToken Blog

Threat Score
55/100

Date Published: 2022-08-08

Date Updated: 2026-06-11

...
...

A researcher discovered an open DigitalOcean staging server hosting Mimikatz binaries and a set of 78 ".creds" filename artifacts suggesting 78 credential-dumping events between 22 July and 7 August 2022; most targeted IPs were in Japan (many on Maxihost), activity clustered by time-of-day, and the author assesses a likely compromise of multiple systems at a Japanese entity and that the operator may be in a UTC+4 timezone.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.