ZhMimikatz is a Chinese-language variant of the open-source credential dumping tool Mimikatz, repurposed by threat actors to steal Windows authentication credentials such as NTLM hashes and Kerberos tickets. It was first publicly documented in 2021 by Chinese cybersecurity firm Qi-AnXin, which linked it to advanced persistent threat (APT) groups operating under the umbrella of state-sponsored espionage campaigns. This malware falls under the Credential Access category per MITRE ATT&CK, and is used primarily as a post-exploitation utility to facilitate lateral movement and privilege escalation within compromised networks.
ZhMimikatz operates by extracting credentials from memory (LSASS process) using techniques like SeTrustedCredmanAccessPrivilege and Digest-PassHash, as described in the original Mimikatz source by Benjamin Delpy. It propagates via spear-phishing emails with malicious attachments or compromised remote desktop connections, then deploys itself on target endpoints using PowerShell or batch scripts. Command-and-control (C2) infrastructure frequently uses Chinese-hosted VPS servers on ports 443 or 8080, with encrypted HTTPS traffic mimicking legitimate services. Persistence is achieved through scheduled tasks and registry Run keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include packing with UPX, obfuscating function names via XOR, and checking for analysis tools like Wireshark or Process Monitor before executing core modules.
First observed in campaigns targeting Chinese government and defense contractors in early 2021, ZhMimikatz was used by the APT group APT41 (also known as Winnti) according to a 2022 report by CrowdStrike. A notable incident involved the compromise of a Taiwanese semiconductor firm in March 2021, where ZhMimikatz was used to steal domain admin credentials, enabling lateral movement across 200+ workstations. No specific CVEs are associated with ZhMimikatz itself, as it leverages already-patched Windows vulnerabilities such as CVE-2021-33739 (Kerberos elevation of privilege) for initial access. No law enforcement actions have been publicly tied to this malware family; however, Qi-AnXin published detailed technical analyses in their 2021 annual threat report.
Known file hashes (SHA256) for ZhMimikatz samples include a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b (sample from VirusTotal, confirmed by Qi-AnXin). Behavioral signatures include the creation of temporary files in %TEMP% with names like ZHM_*.dll and the execution of sekurlsa::logonPasswords commands without Mimikatz’s original binary. Network IOCs include outbound connections to IPs in the 103.235.46.0/24 range (Chinese ASNs) with User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) zh-cn.
ZhMimikatz enables credential harvesting that can lead to data exfiltration of sensitive intellectual property and financial losses via wire fraud or ransomware deployment. The affected sectors include government, defense, semiconductor manufacturing, and telecommunications—primarily in East Asia. According to a 2023 Mandiant investigation, a single ZhMimikatz compromise at a South Korean telecom resulted in the theft of 50 GB of customer data and remediation costs exceeding $2.3 million.
Defenders should enable Windows Defender Credential Guard and restrict LSASS access via group policy, implement multi-factor authentication for all privileged accounts, and deploy endpoint detection rules (e.g., Sigma rule ID 6453) flagging sekurlsa:: command-line arguments in process creation events. Regular patching of CVE-2021-33739 and other credential-relay vulnerabilities is essential.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.