APTMembers
APT

Shared Import Table Ties Four AD Attack Tools to One Build Pipeline

A single imphash links SharpHound, Certify, Rubeus, and DefenderCheck across eight files, while a full Mimikatz suite and matched SafetyKatz forks round out a complete discovery-to-evasion Active Directory toolkit. Build-provenance signals — not tool names — reveal a professionally packaged kit assembled from public GitHub tools.

Jul 10, 2026, 02:42 (UTC+9)Last seenJul 10, 2026Severity82ByCTX TeamActorSandwormQuedaghIOC126MITRE22

A single .NET import-table fingerprint — imphash f34d5f2d4577ed6d9ceec516c1f5a744 — turns up on eight separate files carrying four different public tool identities: SharpHound, Certify, Rubeus, DefenderCheck, and an unlabeled dropper masquerading as RandomName.exe. None of these tools were written by the same author, and none share a codebase.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence