Responder - Tool

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 26, 2025
Last Seen
June 3, 2026

Responder is a tool tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity June 3, 2026.

Overview

Responder is a credential‑harvesting tool that poisons Windows name resolution protocols (NBNS, LLMNR, and MDNS) to capture authentication tokens such as NTLM hashes. It is widely used in Windows network environments to facilitate lateral movement by tricking hosts into authenticating to the attacker’s system. Its significance lies in exploiting insecure, legacy name-resolution mechanisms that remain in many networks, enabling rapid credential theft if not mitigated.

Related Threat Clusters

Recent Intelligence Reports

  • Unpatched NTLM Leakage in Windows search: URI Handler, Same Bug, No CVE, No Fix — Huntress · June 3, 2026
  • Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix — Huntress · June 2, 2026
  • Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation — Mandiant · January 15, 2026
  • Microsoft gives Windows admins a legacy migration headache with WINS sunset — Csoonline · December 1, 2025
  • Old tech, new vulnerabilities: NTLM abuse, ongoing exploitation in 2025 — Securelist · November 26, 2025

CVSS v3.1 Breakdown