Malicious Ntospy Network Provider DLL Registration for Credential Capture

PremiumReviewedSigma · High · v1
Category
registry_set
Author
HuntRule
Published
2026-07-03
Updated
2026-08-28

ATT&CK techniques

Persistence → Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects registration of a malicious Network Provider DLL under the credman service key, matching the Ntospy credential-stealing component used against organizations in the Middle East, Africa and the US per Unit 42. Registering a rogue authentication package as a network provider lets the actor intercept plaintext logon credentials which enables persistent credential theft.

Related detections3 linkedT1556.002 — drag to rearrange
Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Windows PowerShell Copies a DLL into System32 or SysWOW64
Windows Credential Access via Reg Add in LSA Registry Paths
Malicious Ntospy Network Provider DLL Registration for Credential Capture
Pivot detection · T1556.002 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.