Impacket is an open-source Python toolkit that provides low-level access to Windows network protocols (SMB, NTLM, Kerberos) through scriptable utilities (e.g., psexec.py, secretsdump.py, ntlmrelayx).
Overview
Impacket is an open-source Python toolkit that provides low-level access to Windows network protocols (SMB, NTLM, Kerberos) through scriptable utilities (e.g., psexec.py, secretsdump.py, ntlmrelayx). It is widely used for credential dumping, lateral movement, and post-exploitation, with particular relevance to Kerberos delegation and NTLM authentication, making it a prominent tool in both security testing and threat actor workflows.
Related Threat Clusters
-
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Webworm APT Expands Operations to Europe with New Backdoors
The China-aligned APT group Webworm has shifted its focus from Asia to Europe, targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. ESET researchers identified new backdoors,…
12 articles · Updated May 20, 2026 -
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
8 articles · Updated May 5, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Storm-0501 Cybercrime Group Targets Azure with Ransomware Tactics
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their…
2 articles · Updated August 17, 2026 -
Critical Windows Print Spooler Vulnerability CVE-2021-34527 Exploited
CVE-2021-34527, known as 'PrintNightmare', is a critical remote code execution vulnerability affecting the Windows Print Spooler service. Initially thought to be related to CVE-2021-1675, it was identified on July 1,…
2 articles · Updated June 17, 2026 -
Mustang Panda Espionage Campaigns Target India's Government and Energy Sectors
In June 2026, Mustang Panda launched two espionage campaigns targeting India's hydropower sector and government entities. The attacks utilized lure documents related to cooperation agreements with Taiwan, delivering…
2 articles · Updated June 30, 2026 -
New PoC Exploit for NTLM Reflection Bypass Vulnerability on Windows Server
A proof-of-concept (PoC) exploit has been released for a NTLM reflection bypass vulnerability, tracked as CVE-2026-24294, which allows attackers to gain SYSTEM-level access on Windows Server 2025. This vulnerability…
3 articles · Updated June 30, 2026
Recent Intelligence Reports
- NTLMv1 DC Rainbow Tables: Domain Compromise — adscanpro.com · September 8, 2026
- Financially Motivated Threat Actor Breeze Comet Targets Brazil — cloud.google.com · September 1, 2026
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems — Thehackernews · September 1, 2026
- CVE-2026-62911 Enables Pre-Auth RCE on Exchange Server — Socprime · August 31, 2026
- Storm-0501 — attack.mitre.org · August 18, 2026
- BlueHammer — www.cyderes.com · August 13, 2026
- Gunra Ransomware Uses ChaCha20 and RSA-4096 Encryption — Socprime · August 12, 2026
- Six Agencies Warn Gunra Ransomware Hacked MFA at Server Level; Linux Victims May ... — Techtimes · August 11, 2026