Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.003 Credentials from Web Browsers |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAPT3 | APT3 has used tools to dump passwords from browsers. |
| T1555.003 Credentials from Web Browsers |
GroupKimsuky | Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims. |
| T1555.003 Credentials from Web Browsers |
GroupVolt Typhoon | Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials. |
| T1555.003 Credentials from Web Browsers |
GroupPatchwork | Patchwork dumped the login data database from |
| T1555.003 Credentials from Web Browsers |
GroupAPT41 | APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores. |
| T1555.003 Credentials from Web Browsers |
GroupMuddyWater | MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1555.003 Credentials from Web Browsers |
GroupSandworm Team | Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers. |
| T1555.003 Credentials from Web Browsers |
GroupZIRCONIUM | ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAPT37 | APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers. |
| T1555.003 Credentials from Web Browsers |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupTA505 | TA505 has used malware to gather credentials from Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
GroupRedCurl | |
| T1555.003 Credentials from Web Browsers |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupMalteiro | Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView. |
| T1555.003 Credentials from Web Browsers |
GroupAPT42 | APT42 has used custom malware to steal credentials. |
| T1555.003 Credentials from Web Browsers |
GroupLAPSUS$ | LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer. |
| T1555.003 Credentials from Web Browsers |
GroupMolerats | Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims. |
| T1555.003 Credentials from Web Browsers |
GroupInception | Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex. |
| T1555.003 Credentials from Web Browsers |
GroupHEXANE | HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAjax Security Team | Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage. |
| T1555.003 Credentials from Web Browsers |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1555.003 Credentials from Web Browsers |
MalwareTrickBot | TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl. |
| T1555.003 Credentials from Web Browsers |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool. |
| T1555.003 Credentials from Web Browsers |
MalwareSmoke Loader | Smoke Loader searches for credentials stored from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLeaves | RedLeaves can gather browser usernames and passwords. |
| T1555.003 Credentials from Web Browsers |
MalwareInvisibleFerret | InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data. |
| T1555.003 Credentials from Web Browsers |
MalwareRainyDay | RainyDay can use tools to collect credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareNETWIRE | NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareOLDBAIT | OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora. |
| T1555.003 Credentials from Web Browsers |
MalwareCosmicDuke | CosmicDuke collects user credentials, including passwords, for various programs including Web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareMirrorStealer | MirrorStealer can steal credentials stored in browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareEmotet | Emotet has been observed dropping browser password grabber modules. |
| T1555.003 Credentials from Web Browsers |
MalwareOlympic Destroyer | Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareCrimson | Crimson contains a module to steal credentials from Web browsers on the victim machine. |
| T1555.003 Credentials from Web Browsers |
MalwareMachete | Machete collects stored credentials from several web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarePrikormka | A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTRANSLATEXT | TRANSLATEXT has stolen credentials stored in Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareMispadu | Mispadu can steal credentials from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwareXAgentOSX | XAgentOSX contains the getFirefoxPassword function to attempt to locate Firefox passwords. |
| T1555.003 Credentials from Web Browsers |
MalwareKeyBoy | KeyBoy attempts to collect passwords from browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareBeaverTail | BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1555.003 Credentials from Web Browsers |
MalwareROKRAT | ROKRAT can steal credentials stored in Web browsers by querying the sqlite database. |
| T1555.003 Credentials from Web Browsers |
MalwareJavali | Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge. |
| T1555.003 Credentials from Web Browsers |
MalwareLumma Stealer | Lumma Stealer has gathered credential and other information from multiple browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTSCookie | TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareChaes | Chaes can steal login credentials and stored financial information from the browser. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.