FILEMembers
FILE

20-File Kit Bundles Mimikatz, Revoked Driver, PrintNightmare Exploit

A tracked 20-file dossier packages the signed mimikatz credential dumper with a kernel driver still carrying a revoked GlobalSign certificate, a bundled PrintNightmare privilege-escalation exploit, and five Nirsoft password-recovery tools staged under one directory tree. The same kit surfaces across three unrelated espionage clusters, pointing to a commoditized toolkit rather than a coordinated campaign.

Sep 15, 2026, 22:33 (UTC+9)Last seenSep 15, 2026Severity84ByCTX TeamActorSandwormQuedaghIOC34MITRE28RegionsBR

A 20-file dossier tracked by CTX Team reads less like a single implant and more like a toolbox someone packed once and shipped intact. At its center sits the open-source mimikatz credential dumper in its signed 2.2.0.0 release form, flanked by a kernel driver still carrying a certificate its own issuer revoked years ago, a bundled exploit module for the PrintNightmare spooler flaw (CVE-2021-1675), and five Nirsoft password-recovery utilities packed with an identical fingerprint and staged in…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence