Dumping the Active Directory
https://www.bleepingcomputer.com/news/security/trickbot-now-steals-windows-active-directory-credentials/
A new module for the TrickBot trojan has been discovered that targets the Active Directory database stored on compromised Windows domain controllers.
TrickBot is a trojan that when installed will harvest various information from a compromised computer and will then attempt to spread laterally throughout a network to gather more data.