Technique with 6 sub-techniques.View on attack.mitre.org
Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.
Rules on DetectionCode tagged with T1555 or one of its sub-techniques.
| Used by | Procedure example |
|---|---|
| GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| GroupAPT39 | APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords. |
| GroupAPT41 | APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases. |
| GroupEvilnum | Evilnum can collect email credentials from victims. |
| GroupFIN6 | FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP. |
| GroupHEXANE | HEXANE has run `cmdkey` on victim machines to identify stored credentials. |
| GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| GroupMalteiro | Malteiro has obtained credentials from mail clients via NirSoft MailPassView. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles. |
| MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| MalwareBeaverTail | BeaverTail has collected keys stored for Solana stored in `.config/solana/id.json` and other login details associated with macOS within `/Library/Keychains/login.keychain` or for Linux within `/.local/share/keyrings`. |
| MalwareCarberp | Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients. |
| MalwareCosmicDuke | CosmicDuke collects user credentials, including passwords, for various programs including popular instant messaging applications and email clients as well as WLAN keys. |
| MalwareDarkGate | DarkGate use Nirsoft Network Password Recovery or NetPass tools to steal stored RDP credentials in some malware versions. |
| MalwareKGH_SPY | KGH_SPY can collect credentials from WINSCP. |
| ToolLaZagne | LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms. |
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries configured a native CLI to gather a targeted elevated users password using `grep`. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used account credentials they obtained to attempt access to Group Managed Service Account (gMSA) passwords. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.