Gsutil is a tool tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 15, 2026; most recent activity January 15, 2026.
Gsutil is described in the article as a cybersecurity tool/artifact connected to the release of rainbow tables for Net-NTLMv1. Its core role is to provide precomputed tables that can accelerate cracking of Net-NTLMv1 password hashes, with the release framed as a tactic to push faster deprecation of the protocol. This highlights the ongoing risk posed by Net-NTLMv1 and reinforces the need to migrate away from Net-NTLMv1 in enterprise environments.
Mandiant has released rainbow tables that can crack credentials using the Net-NTLMv1 protocol within 12 hours. This legacy Microsoft authentication protocol has been known to expose users to credential theft for over 20…