APTMembers
APT

Complete Mimikatz Toolkit Deployed in Telecom Credential Campaign

A fully intact Mimikatz 2.2.0.0 distribution — all ten components across both architectures — has been deployed alongside Impacket ntlmrelayx relay scripts and cross-platform Chisel tunnel binaries against telecommunications targets. The three-stage chain links PrintNightmare privilege escalation to LSASS credential dumping to HTTP-tunnelled C2 egress, with LDAP relay capability enabling persistent Active Directory manipulation.

Jun 3, 2026, 04:08 (UTC+9)Last seenJun 3, 2026Severity71ByCTX TeamActorSandwormQuedaghIOC22MITRE12

A fully intact Mimikatz 2.2.0.0 distribution — kernel driver, main executable, credential-interception DLL, PrintNightmare exploit module, and distribution archive, all ten components present across both x64 and x86 architectures — has been deployed alongside Impacket ntlmrelayx Python relay scripts and cross-platform Chisel tunnel binaries in a campaign targeting the telecommunications sector.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence