ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1555.003
Credentials from Web Browsers
MalwareGlassWorm

GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers.

T1555.003
Credentials from Web Browsers
MalwareTrojan.Karagany

Trojan.Karagany can steal data and credentials from browsers.

T1555.003
Credentials from Web Browsers
MalwareKONNI

KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera.

T1555.003
Credentials from Web Browsers
MalwareBLUELIGHT

BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale.

T1555.003
Credentials from Web Browsers
MalwareKGH_SPY

KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers.

T1555.003
Credentials from Web Browsers
MalwareRedLine Stealer

RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers.

T1555.003
Credentials from Web Browsers
MalwareGrandoreiro

Grandoreiro can steal cookie data and credentials from Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareSUGARDUMP

SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge.

T1555.003
Credentials from Web Browsers
MalwareXLoader

XLoader can gather credentials from several web browsers.

T1555.003
Credentials from Web Browsers
MalwareMgBot

MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP.

T1555.003
Credentials from Web Browsers
MalwareZebrocy

Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files.

T1555.003
Credentials from Web Browsers
MalwareUnknown Logger

Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine.

T1555.003
Credentials from Web Browsers
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwarePLEAD

PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox.

T1555.003
Credentials from Web Browsers
MalwareRaccoon Stealer

Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers.

T1555.003
Credentials from Web Browsers
MalwareCarberp

Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome.

T1555.003
Credentials from Web Browsers
MalwareProton

Proton gathers credentials for Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareLokibot

Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers.

T1555.003
Credentials from Web Browsers
MalwarePoetRAT

PoetRAT has used a Python tool named Browdec.exe to steal browser credentials.

T1555.003
Credentials from Web Browsers
MalwareMelcoz

Melcoz has the ability to steal credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwarenjRAT

njRAT has a module that steals passwords saved in victim web browsers.

T1555.003
Credentials from Web Browsers
MalwareChChes

ChChes steals credentials stored inside Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwareManjusaka

Manjusaka gathers credentials from Chromium-based browsers.

T1555.003
Credentials from Web Browsers
MalwareAgent Tesla

Agent Tesla can gather credentials from a number of browsers.

T1555.003
Credentials from Web Browsers
MalwareQakBot

QakBot has collected usernames and passwords from Firefox and Chrome.

T1555.003
Credentials from Web Browsers
MalwareCookieMiner

CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials.

T1555.003
Credentials from Web Browsers
MalwarejRAT

jRAT can capture passwords from common web browsers such as Internet Explorer, Google Chrome, and Firefox.

T1555.003
Credentials from Web Browsers
MalwareLizar

Lizar has a module to collect usernames and passwords stored in browsers.

T1555.003
Credentials from Web Browsers
MalwareH1N1

H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook.

T1555.003
Credentials from Web Browsers
MalwareAzorult

Azorult can steal credentials from the victim's browser.

T1555.003
Credentials from Web Browsers
MalwareWarzoneRAT

WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients.

T1555.003
Credentials from Web Browsers
ToolSILENTTRINITY

SILENTTRINITY can collect clear text web credentials for Internet Explorer/Edge.

T1555.003
Credentials from Web Browsers
ToolEmpire

Empire can use modules that extract passwords from common web browsers such as Firefox and Chrome.

T1555.003
Credentials from Web Browsers
ToolImminent Monitor

Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords.

T1555.003
Credentials from Web Browsers
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.

T1555.003
Credentials from Web Browsers
ToolLaZagne

LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.

T1555.003
Credentials from Web Browsers
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1555.003
Credentials from Web Browsers
ToolQuasarRAT

QuasarRAT can obtain passwords from common web browsers.

T1555.004
Windows Credential Manager
CampaignJuicy Mix

During Juicy Mix, OilRig used a Windows Credential Manager stealer for credential access.

T1555.004
Windows Credential Manager
GroupOilRig

OilRig has used credential dumping tool named VALUEVAULT to steal credentials from the Windows Credential Manager.

T1555.004
Windows Credential Manager
GroupTurla

Turla has gathered credentials from the Windows Credential Manager tool.

T1555.004
Windows Credential Manager
GroupStealth Falcon

Stealth Falcon malware gathers passwords from the Windows Credential Vault.

T1555.004
Windows Credential Manager
GroupWizard Spider

Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network.

T1555.004
Windows Credential Manager
MalwareRainyDay

RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials.

T1555.004
Windows Credential Manager
MalwareROKRAT

ROKRAT can steal credentials by leveraging the Windows Vault mechanism.

T1555.004
Windows Credential Manager
MalwareKGH_SPY

KGH_SPY can collect credentials from the Windows Credential Manager.

T1555.004
Windows Credential Manager
MalwareValak

Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager.

T1555.004
Windows Credential Manager
MalwareLizar

Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using `vaultcmd.exe` and another that can collect RDP access credentials using the `CredEnumerateW` function.

T1555.004
Windows Credential Manager
ToolSILENTTRINITY

SILENTTRINITY can gather Windows Vault credentials.

T1555.004
Windows Credential Manager
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.