ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1555.003
Credentials from Web Browsers
MalwareZebrocy

Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files.

T1555.003
Credentials from Web Browsers
MalwareUnknown Logger

Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine.

T1555.003
Credentials from Web Browsers
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwarePLEAD

PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox.

T1555.003
Credentials from Web Browsers
MalwareRaccoon Stealer

Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers.

T1555.003
Credentials from Web Browsers
MalwareCarberp

Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome.

T1555.003
Credentials from Web Browsers
MalwareProton

Proton gathers credentials for Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareLokibot

Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers.

T1555.003
Credentials from Web Browsers
MalwarePoetRAT

PoetRAT has used a Python tool named Browdec.exe to steal browser credentials.

T1555.003
Credentials from Web Browsers
MalwareMelcoz

Melcoz has the ability to steal credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwarenjRAT

njRAT has a module that steals passwords saved in victim web browsers.

T1555.003
Credentials from Web Browsers
MalwareChChes

ChChes steals credentials stored inside Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwareManjusaka

Manjusaka gathers credentials from Chromium-based browsers.

T1555.003
Credentials from Web Browsers
MalwareAgent Tesla

Agent Tesla can gather credentials from a number of browsers.

T1555.003
Credentials from Web Browsers
MalwareQakBot

QakBot has collected usernames and passwords from Firefox and Chrome.

T1555.003
Credentials from Web Browsers
MalwareCookieMiner

CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials.

T1555.003
Credentials from Web Browsers
MalwarejRAT

jRAT can capture passwords from common web browsers such as Internet Explorer, Google Chrome, and Firefox.

T1555.003
Credentials from Web Browsers
MalwareLizar

Lizar has a module to collect usernames and passwords stored in browsers.

T1555.003
Credentials from Web Browsers
MalwareH1N1

H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook.

T1555.003
Credentials from Web Browsers
MalwareAzorult

Azorult can steal credentials from the victim's browser.

T1555.003
Credentials from Web Browsers
MalwareWarzoneRAT

WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients.

T1555.003
Credentials from Web Browsers
ToolSILENTTRINITY

SILENTTRINITY can collect clear text web credentials for Internet Explorer/Edge.

T1555.003
Credentials from Web Browsers
ToolEmpire

Empire can use modules that extract passwords from common web browsers such as Firefox and Chrome.

T1555.003
Credentials from Web Browsers
ToolImminent Monitor

Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords.

T1555.003
Credentials from Web Browsers
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.

T1555.003
Credentials from Web Browsers
ToolLaZagne

LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.

T1555.003
Credentials from Web Browsers
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1555.003
Credentials from Web Browsers
ToolQuasarRAT

QuasarRAT can obtain passwords from common web browsers.

T1555.004
Windows Credential Manager
MalwareRainyDay

RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials.

T1555.004
Windows Credential Manager
MalwareROKRAT

ROKRAT can steal credentials by leveraging the Windows Vault mechanism.

T1555.004
Windows Credential Manager
MalwareKGH_SPY

KGH_SPY can collect credentials from the Windows Credential Manager.

T1555.004
Windows Credential Manager
MalwareValak

Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager.

T1555.004
Windows Credential Manager
MalwareLizar

Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using `vaultcmd.exe` and another that can collect RDP access credentials using the `CredEnumerateW` function.

T1555.004
Windows Credential Manager
ToolSILENTTRINITY

SILENTTRINITY can gather Windows Vault credentials.

T1555.004
Windows Credential Manager
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects.

T1555.004
Windows Credential Manager
ToolMimikatz

Mimikatz contains functionality to acquire credentials from the Windows Credential Manager.

T1555.004
Windows Credential Manager
ToolLaZagne

LaZagne can obtain credentials from Vault files.

T1555.005
Password Managers
MalwareTrickBot

TrickBot can steal passwords from the KeePass open source password manager.

T1555.005
Password Managers
MalwareInvisibleFerret

InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP.

T1555.005
Password Managers
MalwareMarkiRAT

MarkiRAT can gather information from the Keepass password manager.

T1555.005
Password Managers
MalwareProton

Proton gathers credentials in files for 1password.

T1555.005
Password Managers
MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults.

T1555.006
Cloud Secrets Management Stores
MalwareShai-Hulud

Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault.

T1555.006
Cloud Secrets Management Stores
ToolPacu

Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module.

T1555.006
Cloud Secrets Management Stores
ToolTruffleHog

TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history.

T1555.006
Cloud Secrets Management Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials.

T1555.006
Cloud Secrets Management Stores
MalwareMini Shai-Hulud

Mini Shai-Hulud has captured credentials stored in cloud secret stores.

T1555.006
Cloud Secrets Management Stores
MalwareCanisterWorm

CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.

T1556
Modify Authentication Process
MalwareKessel

Kessel has trojanized the <sode>ssh_login</code> and user-auth_pubkey functions to steal plaintext credentials.

T1556
Modify Authentication Process
MalwareEbury

Ebury can intercept private keys using a trojanized ssh-add function.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.