ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1555
Credentials from Password Stores
ToolQuasarRAT

QuasarRAT can obtain passwords from common FTP clients.

T1555
Credentials from Password Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys.

T1555.001
Keychain
MalwareiKitten

iKitten collects the keychains on the system.

T1555.001
Keychain
MalwareCuckoo Stealer

Cuckoo Stealer can capture files from a targeted user's keychain directory.

T1555.001
Keychain
MalwareGreen Lambert

Green Lambert can use Keychain Services API functions to find and collect passwords, such as `SecKeychainFindInternetPassword` and `SecKeychainItemCopyAttributesAndData`.

T1555.001
Keychain
MalwareLightSpy

LightSpy performs an in-memory keychain query via `SecItemCopyMatching()` then formats the retrieved data as a JSON blob for exfiltration.

T1555.001
Keychain
MalwareBeaverTail

BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`.

T1555.001
Keychain
MalwareGlassWorm

GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`.

T1555.001
Keychain
MalwareCalisto

Calisto collects Keychain storage data and copies those passwords/tokens to a file.

T1555.001
Keychain
MalwareMacMa

MacMa can dump credentials from the macOS keychain.

T1555.001
Keychain
MalwareProton

Proton gathers credentials in files for keychains.

T1555.001
Keychain
ToolEmpire

Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential.

T1555.001
Keychain
ToolLaZagne

LaZagne can obtain credentials from macOS Keychains.

T1555.002
Securityd Memory
MalwareKeydnap

Keydnap uses the keychaindump project to read securityd memory.

T1555.003
Credentials from Web Browsers
MalwareTrickBot

TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl.

T1555.003
Credentials from Web Browsers
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool.

T1555.003
Credentials from Web Browsers
MalwareSmoke Loader

Smoke Loader searches for credentials stored from web browsers.

T1555.003
Credentials from Web Browsers
MalwareRedLeaves

RedLeaves can gather browser usernames and passwords.

T1555.003
Credentials from Web Browsers
MalwareInvisibleFerret

InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data.

T1555.003
Credentials from Web Browsers
MalwareRainyDay

RainyDay can use tools to collect credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwareNETWIRE

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.

T1555.003
Credentials from Web Browsers
MalwareOLDBAIT

OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora.

T1555.003
Credentials from Web Browsers
MalwareCosmicDuke

CosmicDuke collects user credentials, including passwords, for various programs including Web browsers.

T1555.003
Credentials from Web Browsers
MalwareMirrorStealer

MirrorStealer can steal credentials stored in browsers.

T1555.003
Credentials from Web Browsers
MalwareEmotet

Emotet has been observed dropping browser password grabber modules.

T1555.003
Credentials from Web Browsers
MalwareOlympic Destroyer

Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwareCrimson

Crimson contains a module to steal credentials from Web browsers on the victim machine.

T1555.003
Credentials from Web Browsers
MalwareMachete

Machete collects stored credentials from several web browsers.

T1555.003
Credentials from Web Browsers
MalwarePrikormka

A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers.

T1555.003
Credentials from Web Browsers
MalwareTRANSLATEXT

TRANSLATEXT has stolen credentials stored in Chrome.

T1555.003
Credentials from Web Browsers
MalwareMispadu

Mispadu can steal credentials from Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwareXAgentOSX

XAgentOSX contains the getFirefoxPassword function to attempt to locate Firefox passwords.

T1555.003
Credentials from Web Browsers
MalwareKeyBoy

KeyBoy attempts to collect passwords from browsers.

T1555.003
Credentials from Web Browsers
MalwareBeaverTail

BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration.

T1555.003
Credentials from Web Browsers
MalwareROKRAT

ROKRAT can steal credentials stored in Web browsers by querying the sqlite database.

T1555.003
Credentials from Web Browsers
MalwareJavali

Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge.

T1555.003
Credentials from Web Browsers
MalwareLumma Stealer

Lumma Stealer has gathered credential and other information from multiple browsers.

T1555.003
Credentials from Web Browsers
MalwareTSCookie

TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers.

T1555.003
Credentials from Web Browsers
MalwareChaes

Chaes can steal login credentials and stored financial information from the browser.

T1555.003
Credentials from Web Browsers
MalwareGlassWorm

GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers.

T1555.003
Credentials from Web Browsers
MalwareTrojan.Karagany

Trojan.Karagany can steal data and credentials from browsers.

T1555.003
Credentials from Web Browsers
MalwareKONNI

KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera.

T1555.003
Credentials from Web Browsers
MalwareBLUELIGHT

BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale.

T1555.003
Credentials from Web Browsers
MalwareKGH_SPY

KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers.

T1555.003
Credentials from Web Browsers
MalwareRedLine Stealer

RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers.

T1555.003
Credentials from Web Browsers
MalwareGrandoreiro

Grandoreiro can steal cookie data and credentials from Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareSUGARDUMP

SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge.

T1555.003
Credentials from Web Browsers
MalwareXLoader

XLoader can gather credentials from several web browsers.

T1555.003
Credentials from Web Browsers
MalwareMgBot

MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.