Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Malware

NPPSPY

NPPSPY is a credential-stealing tool that abuses the Windows Network Provider mechanism to capture cleartext logon credentials. It modifies the Windows Registry to register a malicious Network Provider/listener so that authentication-related traffic from the Winlogon process is redirected from legitimate listening DLLs to the attacker-controlled component. This allows NPPSPY to capture user input and record logon information in cleartext, typically writing the collected credentials to a specified file on the victim machine. The technique is described as stealing cleartext credentials by abusing Network Providers, and a 2020 implementation under the name NPPSpy was uploaded to GitHub by researcher Grzegorz Tworek. Supporting reporting also associates NPPSPY with intrusion activity and broader toolkits, including Check Point reporting that GoldenSMTP/IndigoZebra-related intrusions used the NPPSPY credential stealer, and an NGO ransomware case in which attackers registered a malicious DLL as the provider "credman" to capture Exchange OWA/ECP authentication credentials, gain domain admin access, and laterally move via RDP. High-confidence behavioral indicators mentioned in the content include Registry modification to add the malicious Network Provider, redirection of Winlogon/RPC traffic, and credential output written to local files in cleartext.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence1

“Initial access is typically delivered via password-protected ZIP archives using phishing-style filenames…”

Execution

1 technique
T1574.001DLLEvidence1

“Initial access is typically delivered via password-protected ZIP archives… followed by DLL hijacking to install the first backdoor.”

Persistence

2 techniques
T1112Modify RegistryEvidence2

The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution.

T1556Modify Authentication ProcessEvidence1

...installed Grzegorz Tworek's NPPSpy, configuring the endpoint for a 'man in the middle' attack to collect plain text passwords.

Stealth

1 technique
T1574.001DLLEvidence1

“Initial access is typically delivered via password-protected ZIP archives… followed by DLL hijacking to install the first backdoor.”

Defense Impairment

2 techniques
T1112Modify RegistryEvidence2

The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution.

T1556Modify Authentication ProcessEvidence1

...installed Grzegorz Tworek's NPPSpy, configuring the endpoint for a 'man in the middle' attack to collect plain text passwords.

Credential Access

3 techniques
T1003OS Credential DumpingEvidence1

The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."

T1056.001KeyloggingEvidence1

NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext.

T1556Modify Authentication ProcessEvidence1

...installed Grzegorz Tworek's NPPSpy, configuring the endpoint for a 'man in the middle' attack to collect plain text passwords.

Collection

3 techniques
T1005Data from Local SystemEvidence2

The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.

T1056.001KeyloggingEvidence1

NPPSPY records data entered from the local system logon at Winlogon to capture credentials in cleartext.

T1119Automated CollectionEvidence2

Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.