ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1555.003×

64 examples

TechniqueUsed byProcedure example
T1555.003
Credentials from Web Browsers
MalwareQakBot

QakBot has collected usernames and passwords from Firefox and Chrome.

T1555.003
Credentials from Web Browsers
MalwareCookieMiner

CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials.

T1555.003
Credentials from Web Browsers
MalwarejRAT

jRAT can capture passwords from common web browsers such as Internet Explorer, Google Chrome, and Firefox.

T1555.003
Credentials from Web Browsers
MalwareLizar

Lizar has a module to collect usernames and passwords stored in browsers.

T1555.003
Credentials from Web Browsers
MalwareH1N1

H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook.

T1555.003
Credentials from Web Browsers
MalwareAzorult

Azorult can steal credentials from the victim's browser.

T1555.003
Credentials from Web Browsers
MalwareWarzoneRAT

WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients.

T1555.003
Credentials from Web Browsers
ToolSILENTTRINITY

SILENTTRINITY can collect clear text web credentials for Internet Explorer/Edge.

T1555.003
Credentials from Web Browsers
ToolEmpire

Empire can use modules that extract passwords from common web browsers such as Firefox and Chrome.

T1555.003
Credentials from Web Browsers
ToolImminent Monitor

Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords.

T1555.003
Credentials from Web Browsers
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.

T1555.003
Credentials from Web Browsers
ToolLaZagne

LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.

T1555.003
Credentials from Web Browsers
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1555.003
Credentials from Web Browsers
ToolQuasarRAT

QuasarRAT can obtain passwords from common web browsers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.