Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555 Credentials from Password Stores |
ToolQuasarRAT | QuasarRAT can obtain passwords from common FTP clients. |
| T1555 Credentials from Password Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys. |
| T1555.001 Keychain |
MalwareiKitten | iKitten collects the keychains on the system. |
| T1555.001 Keychain |
MalwareCuckoo Stealer | Cuckoo Stealer can capture files from a targeted user's keychain directory. |
| T1555.001 Keychain |
MalwareGreen Lambert | Green Lambert can use Keychain Services API functions to find and collect passwords, such as `SecKeychainFindInternetPassword` and `SecKeychainItemCopyAttributesAndData`. |
| T1555.001 Keychain |
MalwareLightSpy | LightSpy performs an in-memory keychain query via `SecItemCopyMatching()` then formats the retrieved data as a JSON blob for exfiltration. |
| T1555.001 Keychain |
MalwareBeaverTail | BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`. |
| T1555.001 Keychain |
MalwareGlassWorm | GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`. |
| T1555.001 Keychain |
MalwareCalisto | Calisto collects Keychain storage data and copies those passwords/tokens to a file. |
| T1555.001 Keychain |
MalwareMacMa | MacMa can dump credentials from the macOS keychain. |
| T1555.001 Keychain |
MalwareProton | Proton gathers credentials in files for keychains. |
| T1555.001 Keychain |
ToolEmpire | Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential. |
| T1555.001 Keychain |
ToolLaZagne | LaZagne can obtain credentials from macOS Keychains. |
| T1555.002 Securityd Memory |
MalwareKeydnap | Keydnap uses the keychaindump project to read securityd memory. |
| T1555.003 Credentials from Web Browsers |
MalwareTrickBot | TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl. |
| T1555.003 Credentials from Web Browsers |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool. |
| T1555.003 Credentials from Web Browsers |
MalwareSmoke Loader | Smoke Loader searches for credentials stored from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLeaves | RedLeaves can gather browser usernames and passwords. |
| T1555.003 Credentials from Web Browsers |
MalwareInvisibleFerret | InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data. |
| T1555.003 Credentials from Web Browsers |
MalwareRainyDay | RainyDay can use tools to collect credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareNETWIRE | NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareOLDBAIT | OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora. |
| T1555.003 Credentials from Web Browsers |
MalwareCosmicDuke | CosmicDuke collects user credentials, including passwords, for various programs including Web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareMirrorStealer | MirrorStealer can steal credentials stored in browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareEmotet | Emotet has been observed dropping browser password grabber modules. |
| T1555.003 Credentials from Web Browsers |
MalwareOlympic Destroyer | Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareCrimson | Crimson contains a module to steal credentials from Web browsers on the victim machine. |
| T1555.003 Credentials from Web Browsers |
MalwareMachete | Machete collects stored credentials from several web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarePrikormka | A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTRANSLATEXT | TRANSLATEXT has stolen credentials stored in Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareMispadu | Mispadu can steal credentials from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwareXAgentOSX | XAgentOSX contains the getFirefoxPassword function to attempt to locate Firefox passwords. |
| T1555.003 Credentials from Web Browsers |
MalwareKeyBoy | KeyBoy attempts to collect passwords from browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareBeaverTail | BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1555.003 Credentials from Web Browsers |
MalwareROKRAT | ROKRAT can steal credentials stored in Web browsers by querying the sqlite database. |
| T1555.003 Credentials from Web Browsers |
MalwareJavali | Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge. |
| T1555.003 Credentials from Web Browsers |
MalwareLumma Stealer | Lumma Stealer has gathered credential and other information from multiple browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTSCookie | TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareChaes | Chaes can steal login credentials and stored financial information from the browser. |
| T1555.003 Credentials from Web Browsers |
MalwareGlassWorm | GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTrojan.Karagany | Trojan.Karagany can steal data and credentials from browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareKONNI | KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera. |
| T1555.003 Credentials from Web Browsers |
MalwareBLUELIGHT | BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale. |
| T1555.003 Credentials from Web Browsers |
MalwareKGH_SPY | KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLine Stealer | RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareGrandoreiro | Grandoreiro can steal cookie data and credentials from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareSUGARDUMP | SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge. |
| T1555.003 Credentials from Web Browsers |
MalwareXLoader | XLoader can gather credentials from several web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareMgBot | MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.