Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.003 Credentials from Web Browsers |
MalwareZebrocy | Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files. |
| T1555.003 Credentials from Web Browsers |
MalwareUnknown Logger | Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine. |
| T1555.003 Credentials from Web Browsers |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwarePLEAD | PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox. |
| T1555.003 Credentials from Web Browsers |
MalwareRaccoon Stealer | Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareCarberp | Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareProton | Proton gathers credentials for Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareLokibot | Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarePoetRAT | PoetRAT has used a Python tool named Browdec.exe to steal browser credentials. |
| T1555.003 Credentials from Web Browsers |
MalwareMelcoz | Melcoz has the ability to steal credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarenjRAT | njRAT has a module that steals passwords saved in victim web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareChChes | ChChes steals credentials stored inside Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwareManjusaka | Manjusaka gathers credentials from Chromium-based browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareAgent Tesla | Agent Tesla can gather credentials from a number of browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareQakBot | QakBot has collected usernames and passwords from Firefox and Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareCookieMiner | CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials. |
| T1555.003 Credentials from Web Browsers |
MalwarejRAT | jRAT can capture passwords from common web browsers such as Internet Explorer, Google Chrome, and Firefox. |
| T1555.003 Credentials from Web Browsers |
MalwareLizar | Lizar has a module to collect usernames and passwords stored in browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareH1N1 | H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook. |
| T1555.003 Credentials from Web Browsers |
MalwareAzorult | Azorult can steal credentials from the victim's browser. |
| T1555.003 Credentials from Web Browsers |
MalwareWarzoneRAT | WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients. |
| T1555.003 Credentials from Web Browsers |
ToolSILENTTRINITY | SILENTTRINITY can collect clear text web credentials for Internet Explorer/Edge. |
| T1555.003 Credentials from Web Browsers |
ToolEmpire | Empire can use modules that extract passwords from common web browsers such as Firefox and Chrome. |
| T1555.003 Credentials from Web Browsers |
ToolImminent Monitor | Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords. |
| T1555.003 Credentials from Web Browsers |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI. |
| T1555.003 Credentials from Web Browsers |
ToolLaZagne | LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox. |
| T1555.003 Credentials from Web Browsers |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1555.003 Credentials from Web Browsers |
ToolQuasarRAT | QuasarRAT can obtain passwords from common web browsers. |
| T1555.004 Windows Credential Manager |
MalwareRainyDay | RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials. |
| T1555.004 Windows Credential Manager |
MalwareROKRAT | ROKRAT can steal credentials by leveraging the Windows Vault mechanism. |
| T1555.004 Windows Credential Manager |
MalwareKGH_SPY | KGH_SPY can collect credentials from the Windows Credential Manager. |
| T1555.004 Windows Credential Manager |
MalwareValak | Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager. |
| T1555.004 Windows Credential Manager |
MalwareLizar | Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using `vaultcmd.exe` and another that can collect RDP access credentials using the `CredEnumerateW` function. |
| T1555.004 Windows Credential Manager |
ToolSILENTTRINITY | SILENTTRINITY can gather Windows Vault credentials. |
| T1555.004 Windows Credential Manager |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects. |
| T1555.004 Windows Credential Manager |
ToolMimikatz | Mimikatz contains functionality to acquire credentials from the Windows Credential Manager. |
| T1555.004 Windows Credential Manager |
ToolLaZagne | LaZagne can obtain credentials from Vault files. |
| T1555.005 Password Managers |
MalwareTrickBot | TrickBot can steal passwords from the KeePass open source password manager. |
| T1555.005 Password Managers |
MalwareInvisibleFerret | InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP. |
| T1555.005 Password Managers |
MalwareMarkiRAT | MarkiRAT can gather information from the Keepass password manager. |
| T1555.005 Password Managers |
MalwareProton | Proton gathers credentials in files for 1password. |
| T1555.005 Password Managers |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults. |
| T1555.006 Cloud Secrets Management Stores |
MalwareShai-Hulud | Shai-Hulud has gathered secrets from AWS Secrets and GCP Secret Manager. Shai-Hulud has also gathered data from Azure Key Vault. |
| T1555.006 Cloud Secrets Management Stores |
ToolPacu | Pacu can retrieve secrets from the AWS Secrets Manager via the enum_secrets module. |
| T1555.006 Cloud Secrets Management Stores |
ToolTruffleHog | TruffleHog can obtain secrets from AWS Secrets and GCP Secret Manager. TruffleHog has also gathered passwords, secrets and API keys from source repositories, .env files, and git history. |
| T1555.006 Cloud Secrets Management Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can enumerate multiple filesystem paths to extract credentials for AWS, GCP, and Azure including Identity Access Management (IAM) credentials. |
| T1555.006 Cloud Secrets Management Stores |
MalwareMini Shai-Hulud | Mini Shai-Hulud has captured credentials stored in cloud secret stores. |
| T1555.006 Cloud Secrets Management Stores |
MalwareCanisterWorm | CanisterWorm has gathered credentials from Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure. |
| T1556 Modify Authentication Process |
MalwareKessel | Kessel has trojanized the <sode>ssh_login</code> and |
| T1556 Modify Authentication Process |
MalwareEbury | Ebury can intercept private keys using a trojanized |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.