Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555 Credentials from Password Stores |
GroupEvilnum | Evilnum can collect email credentials from victims. |
| T1555 Credentials from Password Stores |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email. |
| T1555 Credentials from Password Stores |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP. |
| T1555 Credentials from Password Stores |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1555 Credentials from Password Stores |
GroupAPT39 | APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords. |
| T1555 Credentials from Password Stores |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555 Credentials from Password Stores |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from multiple sources, including Windows Credential Vault and Outlook. |
| T1555 Credentials from Password Stores |
GroupMalteiro | Malteiro has obtained credentials from mail clients via NirSoft MailPassView. |
| T1555 Credentials from Password Stores |
GroupHEXANE | HEXANE has run `cmdkey` on victim machines to identify stored credentials. |
| T1555 Credentials from Password Stores |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1555 Credentials from Password Stores |
MalwareMatryoshka | Matryoshka is capable of stealing Outlook passwords. |
| T1555 Credentials from Password Stores |
MalwareNETWIRE | NETWIRE can retrieve passwords from messaging and mail client applications. |
| T1555 Credentials from Password Stores |
MalwareOLDBAIT | OLDBAIT collects credentials from several email clients. |
| T1555 Credentials from Password Stores |
MalwareCosmicDuke | CosmicDuke collects user credentials, including passwords, for various programs including popular instant messaging applications and email clients as well as WLAN keys. |
| T1555 Credentials from Password Stores |
MalwareMirrorStealer | MirrorStealer has the ability to steal credentials from email clients. |
| T1555 Credentials from Password Stores |
MalwarePrikormka | A module in Prikormka collects passwords stored in applications installed on the victim. |
| T1555 Credentials from Password Stores |
MalwareMispadu | Mispadu has obtained credentials from mail clients via NirSoft MailPassView. |
| T1555 Credentials from Password Stores |
MalwareBeaverTail | BeaverTail has collected keys stored for Solana stored in `.config/solana/id.json` and other login details associated with macOS within `/Library/Keychains/login.keychain` or for Linux within `/.local/share/keyrings`. |
| T1555 Credentials from Password Stores |
MalwareDarkGate | DarkGate use Nirsoft Network Password Recovery or NetPass tools to steal stored RDP credentials in some malware versions. |
| T1555 Credentials from Password Stores |
MalwareKGH_SPY | KGH_SPY can collect credentials from WINSCP. |
| T1555 Credentials from Password Stores |
MalwareRedLine Stealer | RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients. |
| T1555 Credentials from Password Stores |
MalwareXLoader | XLoader can collect credentials stored in email clients. |
| T1555 Credentials from Password Stores |
MalwareMgBot | MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software. |
| T1555 Credentials from Password Stores |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as The Bat!, Yahoo!, Mail.ru, Passport.Net, Google Talk, and Microsoft Outlook. |
| T1555 Credentials from Password Stores |
MalwarePLEAD | PLEAD has the ability to steal saved passwords from Microsoft Outlook. |
| T1555 Credentials from Password Stores |
MalwareCarberp | Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients. |
| T1555 Credentials from Password Stores |
MalwareLokibot | Lokibot has stolen credentials from multiple applications and data sources including Windows OS credentials, email clients, FTP, and SFTP clients. |
| T1555 Credentials from Password Stores |
MalwareManjusaka | Manjusaka extracts credentials from the Windows Registry associated with Premiumsoft Navicat, a utility used to facilitate access to various database types. |
| T1555 Credentials from Password Stores |
MalwareAgent Tesla | Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles. |
| T1555 Credentials from Password Stores |
MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| T1555 Credentials from Password Stores |
ToolPoshC2 | PoshC2 can decrypt passwords stored in the RDCMan configuration file. |
| T1555 Credentials from Password Stores |
ToolMimikatz | Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI. |
| T1555 Credentials from Password Stores |
ToolLaZagne | LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms. |
| T1555 Credentials from Password Stores |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1555 Credentials from Password Stores |
ToolQuasarRAT | QuasarRAT can obtain passwords from common FTP clients. |
| T1555 Credentials from Password Stores |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys. |
| T1555.001 Keychain |
GroupContagious Interview | Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain. |
| T1555.001 Keychain |
MalwareiKitten | iKitten collects the keychains on the system. |
| T1555.001 Keychain |
MalwareCuckoo Stealer | Cuckoo Stealer can capture files from a targeted user's keychain directory. |
| T1555.001 Keychain |
MalwareGreen Lambert | Green Lambert can use Keychain Services API functions to find and collect passwords, such as `SecKeychainFindInternetPassword` and `SecKeychainItemCopyAttributesAndData`. |
| T1555.001 Keychain |
MalwareLightSpy | LightSpy performs an in-memory keychain query via `SecItemCopyMatching()` then formats the retrieved data as a JSON blob for exfiltration. |
| T1555.001 Keychain |
MalwareBeaverTail | BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`. |
| T1555.001 Keychain |
MalwareGlassWorm | GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`. |
| T1555.001 Keychain |
MalwareCalisto | Calisto collects Keychain storage data and copies those passwords/tokens to a file. |
| T1555.001 Keychain |
MalwareMacMa | MacMa can dump credentials from the macOS keychain. |
| T1555.001 Keychain |
MalwareProton | Proton gathers credentials in files for keychains. |
| T1555.001 Keychain |
ToolEmpire | Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential. |
| T1555.001 Keychain |
ToolLaZagne | LaZagne can obtain credentials from macOS Keychains. |
| T1555.002 Securityd Memory |
MalwareKeydnap | Keydnap uses the keychaindump project to read securityd memory. |
| T1555.003 Credentials from Web Browsers |
CampaignJuicy Mix | During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.