Gifting User Passwords to Adversaries With NPPSPY | Huntress
ID: 7f82a11e-3375-5598-9b19-bbfcacebddb2
STIX ID: report--7f82a11e-3375-5598-9b19-bbfcacebddb2
Feed Name: Huntress Blog
Threat Score
Huntress documented a confirmed intrusion where adversaries used the NPPSPY method — registering an attacker-controlled Network Provider DLL to intercept Winlogon cleartext credentials and persist them to disk (example: C:\Windows\Temp\tmpCQOF.tmp), including credentials observed from an Exchange server; the report details IOCs (registry values, service name 'logincontroll', malicious DLL path), detection approaches, and remediation steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
