NPPSPY

MITRE
Malware Type:
Tool
First seen:
Unknown
Last seen:
Unknown
Details:

NPPSPY is an implementation of a theoretical mechanism first presented in 2004 for capturing credentials submitted to a Windows system via a rogue Network Provider API item. NPPSPY captures credentials following submission and writes them to a file on the victim system for follow-on exfiltration.(Citation: Huntress NPPSPY 2022)(Citation: Polak NPPSPY 2004)

Associated Techniques (7)
ID ATT&CK Tactics
T1005 Data from Local System -
T1056 Input Capture -
T1112 Modify Registry -
T1119 Automated Collection -
T1552 Unsecured Credentials -
T1557 Adversary-in-the-Middle -
T1656 Impersonation -
Metadata
ID: 698
Created: 13/01/2026 17:48
Updated: 06/03/2026 16:00