NTLM Relay - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 26, 2025
Last Seen
June 17, 2026

NTLM Relay is a mitre_attack tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity June 17, 2026.

Overview

NTLM Relay is a MITRE ATT&CK technique that exploits the NTLM authentication flow to relay credentials from a compromised host to a target service, enabling lateral movement and potential privilege escalation in Windows environments. It hinges on NTLM (often NTLMv1) and is notable in networks where NTLMv1 remains enabled or where relay pathways (SMB/HTTP) can be abused, making detection and mitigation essential.

Related Threat Clusters

Recent Intelligence Reports

  • Exploiting Cve 2023 23397 Microsoft Outlook Elevation Of Privilege Vulnerability — www.mdsec.co.uk · June 17, 2026
  • Microsoft to disable NTLM by default in future Windows releases — Bleepingcomputer · January 30, 2026
  • Mandiant pushes organizations to dump insecure NTLMv1 by releasing a way to crack it — Csoonline · January 19, 2026
  • Old tech, new vulnerabilities: NTLM abuse, ongoing exploitation in 2025 — Securelist · November 26, 2025

CVSS v3.1 Breakdown