Skip to content

Attackers Downgrade WDigest Protection to Dump Plaintext Credentials With Mimikatz

Gbhackers Mayura Kathir July 2, 2026

An incident that began with innocuous enumeration commands but quickly escalated into a focused, multi-stage effort to impair detection and extract credentials. The intruder uploaded a steganographic webshell to an IIS server, used the process w3wp.exe to run OS reconnaissance such as whoami, and then deployed an extensive defence-impairment script (i.bat) that prefaced a credential-dump […]