Credentials from Web Browsers

T1555.003

Sub-technique of T1555 Credentials from Password Stores.View on attack.mitre.org

About this technique

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.

For example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, AppData\Local\Google\Chrome\User Data\Default\Login Data and executing a SQL query: SELECT action_url, username_value, password_value FROM logins;. The plaintext password can then be obtained by passing the encrypted credentials to the Windows API function CryptUnprotectData, which uses the victim’s cached logon credentials as the decryption key.

Adversaries have executed similar procedures for common web browsers such as FireFox, Safari, Edge, etc. Windows stores Internet Explorer and Microsoft Edge credentials in Credential Lockers managed by the Windows Credential Manager.

Adversaries may also acquire credentials by searching web browser process memory for patterns that commonly match credentials.

After acquiring credentials from web browsers, adversaries may attempt to recycle the credentials across different systems and/or accounts in order to expand access. This can result in significantly furthering an adversary's objective in cases where credentials gained from web browsers overlap with privileged accounts (e.g. domain administrator).

Detection rules12

Rules on DetectionCode tagged with T1555.003.

Sigma7

RuleLevelLog source
HackTool - WinPwn Executionhighwindows / process_creation
HackTool - WinPwn Execution - ScriptBlockhighwindows / ps_script
SQLite Chromium Profile Data DB Accesshighwindows / process_creation
Access to Browser Login Datamediumwindows / ps_script
Potential Browser Data Stealingmediumwindows / process_creation
PUA - WebBrowserPassView Executionmediumwindows / process_creation
Suspicious File Access to Browser Credential Storagelowwindows / file_access

Splunk5

RuleTypeRiskData source
Non Chrome Process Accessing Chrome Default DirAnomalyNULLWindows Event Log Security 4663
Non Firefox Process Access Firefox Profile DirAnomalyNULLWindows Event Log Security 4663
Possible Browser Pass View ParameterHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Credentials from Password Stores Chrome Copied in TEMP DirTTPNULLSysmon EventID 11
Windows Credentials from Web Browsers Saved in TEMP FolderTTPNULLSysmon EventID 11

Groups23

Software64

Show 40 more

Campaigns2

Procedure examples89

Groups23

Used byProcedure example
GroupAjax Security Team

Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage.

GroupAPT3

APT3 has used tools to dump passwords from browsers.

GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

GroupAPT37

APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers.

GroupAPT41

APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.

GroupAPT42

APT42 has used custom malware to steal credentials.

GroupFIN6

FIN6 has used the Stealer One credential stealer to target web browsers.

GroupHEXANE

HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome.

View all 23 groups examples

Software64

Used byProcedure example
MalwareAgent Tesla

Agent Tesla can gather credentials from a number of browsers.

MalwareAzorult

Azorult can steal credentials from the victim's browser.

MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool.

MalwareBeaverTail

BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration.

MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.

MalwareBLUELIGHT

BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale.

MalwareCarberp

Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome.

MalwareChaes

Chaes can steal login credentials and stored financial information from the browser.

View all 64 software examples

Campaigns2

Used byProcedure example
CampaignJuicy Mix

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome.

References5

  1. FireEye HawkEye Malware July 2017 Open source
    Swapnil Patil, Yogesh Londhe. (2017, July 25). HawkEye Credential Theft Malware Distributed in Recent Phishing Campaign. Retrieved June 18, 2019.
  2. GitHub Mimikittenz July 2016 Open source
    Jamieson O'Reilly (putterpanda). (2016, July 4). mimikittenz. Retrieved June 20, 2019.
  3. Microsoft CryptUnprotectData April 2018 Open source
    Microsoft. (2018, April 12). CryptUnprotectData function. Retrieved June 18, 2019.
  4. Proofpoint Vega Credential Stealer May 2018 Open source
    Proofpoint. (2018, May 10). New Vega Stealer shines brightly in targeted campaign . Retrieved June 18, 2019.
  5. Talos Olympic Destroyer 2018 Open source
    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.