
20-File Kit Bundles Mimikatz, Revoked Driver, PrintNightmare Exploit
A tracked 20-file dossier packages the signed mimikatz credential dumper with a kernel driver still carrying a revoked GlobalSign certificate, a bundled PrintNightmare privilege-escalation exploit, and five Nirsoft password-recovery tools staged under one directory tree. The same kit surfaces across three unrelated espionage clusters, pointing to a commoditized toolkit rather than a coordinated campaign.
A 20-file dossier tracked by CTX Team reads less like a single implant and more like a toolbox someone packed once and shipped intact. At its center sits the open-source mimikatz credential dumper in its signed 2.2.0.0 release form, flanked by a kernel driver still carrying a certificate its own issuer revoked years ago, a bundled exploit module for the PrintNightmare spooler flaw (CVE-2021-1675), and five Nirsoft password-recovery utilities packed with an identical fingerprint and staged in…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read