Sub-technique of T1555 Credentials from Password Stores.View on attack.mitre.org
Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers.
For example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, AppData\Local\Google\Chrome\User Data\Default\Login Data and executing a SQL query: SELECT action_url, username_value, password_value FROM logins;. The plaintext password can then be obtained by passing the encrypted credentials to the Windows API function CryptUnprotectData, which uses the victim’s cached logon credentials as the decryption key.
Adversaries have executed similar procedures for common web browsers such as FireFox, Safari, Edge, etc. Windows stores Internet Explorer and Microsoft Edge credentials in Credential Lockers managed by the Windows Credential Manager.
Adversaries may also acquire credentials by searching web browser process memory for patterns that commonly match credentials.
After acquiring credentials from web browsers, adversaries may attempt to recycle the credentials across different systems and/or accounts in order to expand access. This can result in significantly furthering an adversary's objective in cases where credentials gained from web browsers overlap with privileged accounts (e.g. domain administrator).
Rules on DetectionCode tagged with T1555.003.
| Rule | Level | Log source |
|---|---|---|
| HackTool - WinPwn Execution | high | windows / process_creation |
| HackTool - WinPwn Execution - ScriptBlock | high | windows / ps_script |
| SQLite Chromium Profile Data DB Access | high | windows / process_creation |
| Access to Browser Login Data | medium | windows / ps_script |
| Potential Browser Data Stealing | medium | windows / process_creation |
| PUA - WebBrowserPassView Execution | medium | windows / process_creation |
| Suspicious File Access to Browser Credential Storage | low | windows / file_access |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Non Chrome Process Accessing Chrome Default Dir | Anomaly | NULL | Windows Event Log Security 4663 |
| Non Firefox Process Access Firefox Profile Dir | Anomaly | NULL | Windows Event Log Security 4663 |
| Possible Browser Pass View Parameter | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Credentials from Password Stores Chrome Copied in TEMP Dir | TTP | NULL | Sysmon EventID 11 |
| Windows Credentials from Web Browsers Saved in TEMP Folder | TTP | NULL | Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| GroupAjax Security Team | Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage. |
| GroupAPT3 | APT3 has used tools to dump passwords from browsers. |
| GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| GroupAPT37 | APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers. |
| GroupAPT41 | APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores. |
| GroupAPT42 | APT42 has used custom malware to steal credentials. |
| GroupFIN6 | FIN6 has used the Stealer One credential stealer to target web browsers. |
| GroupHEXANE | HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla can gather credentials from a number of browsers. |
| MalwareAzorult | Azorult can steal credentials from the victim's browser. |
| MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool. |
| MalwareBeaverTail | BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer. |
| MalwareBLUELIGHT | BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale. |
| MalwareCarberp | Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome. |
| MalwareChaes | Chaes can steal login credentials and stored financial information from the browser. |
| Used by | Procedure example |
|---|---|
| CampaignJuicy Mix | During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.