logo

Gifting User Passwords to Adversaries With NPPSPY | Huntress

ID: 7f82a11e-3375-5598-9b19-bbfcacebddb2

STIX ID: report--7f82a11e-3375-5598-9b19-bbfcacebddb2

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-06-25

Date Updated: 2026-04-28

...
...

Huntress documented a confirmed intrusion where adversaries used the NPPSPY method — registering an attacker-controlled Network Provider DLL to intercept Winlogon cleartext credentials and persist them to disk (example: C:\Windows\Temp\tmpCQOF.tmp), including credentials observed from an Exchange server; the report details IOCs (registry values, service name 'logincontroll', malicious DLL path), detection approaches, and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.