Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.003 Credentials from Web Browsers |
MalwareGlassWorm | GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTrojan.Karagany | Trojan.Karagany can steal data and credentials from browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareKONNI | KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera. |
| T1555.003 Credentials from Web Browsers |
MalwareBLUELIGHT | BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale. |
| T1555.003 Credentials from Web Browsers |
MalwareKGH_SPY | KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLine Stealer | RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareGrandoreiro | Grandoreiro can steal cookie data and credentials from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareSUGARDUMP | SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge. |
| T1555.003 Credentials from Web Browsers |
MalwareXLoader | XLoader can gather credentials from several web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareMgBot | MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP. |
| T1555.003 Credentials from Web Browsers |
MalwareZebrocy | Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files. |
| T1555.003 Credentials from Web Browsers |
MalwareUnknown Logger | Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine. |
| T1555.003 Credentials from Web Browsers |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwarePLEAD | PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox. |
| T1555.003 Credentials from Web Browsers |
MalwareRaccoon Stealer | Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareCarberp | Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareProton | Proton gathers credentials for Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareLokibot | Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarePoetRAT | PoetRAT has used a Python tool named Browdec.exe to steal browser credentials. |
| T1555.003 Credentials from Web Browsers |
MalwareMelcoz | Melcoz has the ability to steal credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarenjRAT | njRAT has a module that steals passwords saved in victim web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareChChes | ChChes steals credentials stored inside Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwareManjusaka | Manjusaka gathers credentials from Chromium-based browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareAgent Tesla | Agent Tesla can gather credentials from a number of browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareQakBot | QakBot has collected usernames and passwords from Firefox and Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareCookieMiner | CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials. |
| T1555.003 Credentials from Web Browsers |
MalwarejRAT | jRAT can capture passwords from common web browsers such as Internet Explorer, Google Chrome, and Firefox. |
| T1555.003 Credentials from Web Browsers |
MalwareLizar | Lizar has a module to collect usernames and passwords stored in browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareH1N1 | H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook. |
| T1555.003 Credentials from Web Browsers |
MalwareAzorult | Azorult can steal credentials from the victim's browser. |
| T1555.003 Credentials from Web Browsers |
MalwareWarzoneRAT | WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients. |
| T1555.003 Credentials from Web Browsers |
ToolSILENTTRINITY | SILENTTRINITY can collect clear text web credentials for Internet Explorer/Edge. |
| T1555.003 Credentials from Web Browsers |
ToolEmpire | Empire can use modules that extract passwords from common web browsers such as Firefox and Chrome. |
| T1555.003 Credentials from Web Browsers |
ToolImminent Monitor | Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords. |
| T1555.003 Credentials from Web Browsers |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI. |
| T1555.003 Credentials from Web Browsers |
ToolLaZagne | LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox. |
| T1555.003 Credentials from Web Browsers |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1555.003 Credentials from Web Browsers |
ToolQuasarRAT | QuasarRAT can obtain passwords from common web browsers. |
| T1555.004 Windows Credential Manager |
CampaignJuicy Mix | During Juicy Mix, OilRig used a Windows Credential Manager stealer for credential access. |
| T1555.004 Windows Credential Manager |
GroupOilRig | OilRig has used credential dumping tool named VALUEVAULT to steal credentials from the Windows Credential Manager. |
| T1555.004 Windows Credential Manager |
GroupTurla | Turla has gathered credentials from the Windows Credential Manager tool. |
| T1555.004 Windows Credential Manager |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from the Windows Credential Vault. |
| T1555.004 Windows Credential Manager |
GroupWizard Spider | Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network. |
| T1555.004 Windows Credential Manager |
MalwareRainyDay | RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials. |
| T1555.004 Windows Credential Manager |
MalwareROKRAT | ROKRAT can steal credentials by leveraging the Windows Vault mechanism. |
| T1555.004 Windows Credential Manager |
MalwareKGH_SPY | KGH_SPY can collect credentials from the Windows Credential Manager. |
| T1555.004 Windows Credential Manager |
MalwareValak | Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager. |
| T1555.004 Windows Credential Manager |
MalwareLizar | Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using `vaultcmd.exe` and another that can collect RDP access credentials using the `CredEnumerateW` function. |
| T1555.004 Windows Credential Manager |
ToolSILENTTRINITY | SILENTTRINITY can gather Windows Vault credentials. |
| T1555.004 Windows Credential Manager |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.