Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:52:55 UTC Home > List all groups > List all tools > List all groups using tool Impacket Tool: Impacket Names Impacket Category Tools Type Credential stealer, Info stealer Description Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks. Information MITRE ATT&CK Last change to this tool card: 22 April 2020 Download this tool card in JSON format All groups using tool Impacket Changed Name Country Observed APT groups ALPHV, BlackCat Gang [Unknown] 2021-Mar 2024 ↳ Subgroup: Scattered Spider [Unknown] 2022-Aug 2025 Berserk Bear, Dragonfly 2.0 2015-May 2017 Cadet Blizzard 2020-Jun 2024 Energetic Bear, Dragonfly 2010-Mar 2022 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8e29a0d3-324b-43f0-b4f8-f81d18a2744e Page 1 of 2 LightBasin 2016         ↳ Subgroup: DEV-0270, Nemesis Kitten 2022-Nov 2023     Mustang Panda, Bronze President 2012-Jun 2025     Operation Ghostwriter 2017-Jan 2025   Operation Harvest 2016     Operation Jacana 2023     RedCurl [Unknown] 2018-Mar 2025     RedFoxtrot 2014-Aug 2021     Sofacy, APT 28, Fancy Bear, Sednit 2004-Apr 2025   Stone Panda, APT 10, menuPass 2006-Mar 2025   ToddyCat 2020-2024     Volt Typhoon 2020-Aug 2025 17 groups listed (17 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8e29a0d3-324b-43f0-b4f8-f81d18a2744e https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8e29a0d3-324b-43f0-b4f8-f81d18a2744e Page 2 of 2