The DonPapi tool allows cybercriminals and pentesters to easily obtain credentials from compromised systems. The main goal and idea of DonPapi is to perform information gathering while remaining out of the view of antivirus solutions.

Unit42 says that DonPapi is used by ‘The Ransom Cartel’ to search machines for files that might contain credentials.


