Tool
MailPassView
- First Reported
- Dec 17, 2025
- Latest Reported
- Dec 17, 2025
Reported Context (1)
- in the report as a starting point, we extracted two SHA-256 IoCs of credential-recovery utilities, "MailPassView" and "WebBrowserPassView", both used by the Lazarus group for credential harvesting. Hunt.io and Acronis Trace Lazarus and Kimsuky Infrastructure Across Campaigns
Malware (6)
People (1)
Threat Actors (4)
MITRE ATT&CK (3)
Vendors (2)
Products (1)
Tools (28)
Countries (4)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.