ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1555.003×

64 examples

TechniqueUsed byProcedure example
T1555.003
Credentials from Web Browsers
MalwareTrickBot

TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl.

T1555.003
Credentials from Web Browsers
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool.

T1555.003
Credentials from Web Browsers
MalwareSmoke Loader

Smoke Loader searches for credentials stored from web browsers.

T1555.003
Credentials from Web Browsers
MalwareRedLeaves

RedLeaves can gather browser usernames and passwords.

T1555.003
Credentials from Web Browsers
MalwareInvisibleFerret

InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data.

T1555.003
Credentials from Web Browsers
MalwareRainyDay

RainyDay can use tools to collect credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwareNETWIRE

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.

T1555.003
Credentials from Web Browsers
MalwareOLDBAIT

OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora.

T1555.003
Credentials from Web Browsers
MalwareCosmicDuke

CosmicDuke collects user credentials, including passwords, for various programs including Web browsers.

T1555.003
Credentials from Web Browsers
MalwareMirrorStealer

MirrorStealer can steal credentials stored in browsers.

T1555.003
Credentials from Web Browsers
MalwareEmotet

Emotet has been observed dropping browser password grabber modules.

T1555.003
Credentials from Web Browsers
MalwareOlympic Destroyer

Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwareCrimson

Crimson contains a module to steal credentials from Web browsers on the victim machine.

T1555.003
Credentials from Web Browsers
MalwareMachete

Machete collects stored credentials from several web browsers.

T1555.003
Credentials from Web Browsers
MalwarePrikormka

A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers.

T1555.003
Credentials from Web Browsers
MalwareTRANSLATEXT

TRANSLATEXT has stolen credentials stored in Chrome.

T1555.003
Credentials from Web Browsers
MalwareMispadu

Mispadu can steal credentials from Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwareXAgentOSX

XAgentOSX contains the getFirefoxPassword function to attempt to locate Firefox passwords.

T1555.003
Credentials from Web Browsers
MalwareKeyBoy

KeyBoy attempts to collect passwords from browsers.

T1555.003
Credentials from Web Browsers
MalwareBeaverTail

BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration.

T1555.003
Credentials from Web Browsers
MalwareROKRAT

ROKRAT can steal credentials stored in Web browsers by querying the sqlite database.

T1555.003
Credentials from Web Browsers
MalwareJavali

Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge.

T1555.003
Credentials from Web Browsers
MalwareLumma Stealer

Lumma Stealer has gathered credential and other information from multiple browsers.

T1555.003
Credentials from Web Browsers
MalwareTSCookie

TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers.

T1555.003
Credentials from Web Browsers
MalwareChaes

Chaes can steal login credentials and stored financial information from the browser.

T1555.003
Credentials from Web Browsers
MalwareGlassWorm

GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers.

T1555.003
Credentials from Web Browsers
MalwareTrojan.Karagany

Trojan.Karagany can steal data and credentials from browsers.

T1555.003
Credentials from Web Browsers
MalwareKONNI

KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera.

T1555.003
Credentials from Web Browsers
MalwareBLUELIGHT

BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale.

T1555.003
Credentials from Web Browsers
MalwareKGH_SPY

KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers.

T1555.003
Credentials from Web Browsers
MalwareRedLine Stealer

RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers.

T1555.003
Credentials from Web Browsers
MalwareGrandoreiro

Grandoreiro can steal cookie data and credentials from Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareSUGARDUMP

SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge.

T1555.003
Credentials from Web Browsers
MalwareXLoader

XLoader can gather credentials from several web browsers.

T1555.003
Credentials from Web Browsers
MalwareMgBot

MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP.

T1555.003
Credentials from Web Browsers
MalwareZebrocy

Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files.

T1555.003
Credentials from Web Browsers
MalwareUnknown Logger

Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine.

T1555.003
Credentials from Web Browsers
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwarePLEAD

PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox.

T1555.003
Credentials from Web Browsers
MalwareRaccoon Stealer

Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers.

T1555.003
Credentials from Web Browsers
MalwareCarberp

Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome.

T1555.003
Credentials from Web Browsers
MalwareProton

Proton gathers credentials for Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareLokibot

Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers.

T1555.003
Credentials from Web Browsers
MalwarePoetRAT

PoetRAT has used a Python tool named Browdec.exe to steal browser credentials.

T1555.003
Credentials from Web Browsers
MalwareMelcoz

Melcoz has the ability to steal credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwarenjRAT

njRAT has a module that steals passwords saved in victim web browsers.

T1555.003
Credentials from Web Browsers
MalwareChChes

ChChes steals credentials stored inside Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwareManjusaka

Manjusaka gathers credentials from Chromium-based browsers.

T1555.003
Credentials from Web Browsers
MalwareAgent Tesla

Agent Tesla can gather credentials from a number of browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.