ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1555.003
Credentials from Web Browsers
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome.

T1555.003
Credentials from Web Browsers
GroupAPT3

APT3 has used tools to dump passwords from browsers.

T1555.003
Credentials from Web Browsers
GroupKimsuky

Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.

T1555.003
Credentials from Web Browsers
GroupVolt Typhoon

Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials.

T1555.003
Credentials from Web Browsers
GroupPatchwork

Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data.

T1555.003
Credentials from Web Browsers
GroupAPT41

APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.

T1555.003
Credentials from Web Browsers
GroupMuddyWater

MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.

T1555.003
Credentials from Web Browsers
GroupFIN6

FIN6 has used the Stealer One credential stealer to target web browsers.

T1555.003
Credentials from Web Browsers
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1555.003
Credentials from Web Browsers
GroupSandworm Team

Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers.

T1555.003
Credentials from Web Browsers
GroupZIRCONIUM

ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome.

T1555.003
Credentials from Web Browsers
GroupAPT37

APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers.

T1555.003
Credentials from Web Browsers
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.

T1555.003
Credentials from Web Browsers
GroupTA505

TA505 has used malware to gather credentials from Internet Explorer.

T1555.003
Credentials from Web Browsers
GroupRedCurl

RedCurl used LaZagne to obtain passwords from web browsers.

T1555.003
Credentials from Web Browsers
GroupStealth Falcon

Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome.

T1555.003
Credentials from Web Browsers
GroupMalteiro

Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView.

T1555.003
Credentials from Web Browsers
GroupAPT42

APT42 has used custom malware to steal credentials.

T1555.003
Credentials from Web Browsers
GroupLAPSUS$

LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer.

T1555.003
Credentials from Web Browsers
GroupMolerats

Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.

T1555.003
Credentials from Web Browsers
GroupInception

Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex.

T1555.003
Credentials from Web Browsers
GroupHEXANE

HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome.

T1555.003
Credentials from Web Browsers
GroupAjax Security Team

Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage.

T1555.003
Credentials from Web Browsers
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

T1555.003
Credentials from Web Browsers
MalwareTrickBot

TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl.

T1555.003
Credentials from Web Browsers
MalwareBackdoor.Oldrea

Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool.

T1555.003
Credentials from Web Browsers
MalwareSmoke Loader

Smoke Loader searches for credentials stored from web browsers.

T1555.003
Credentials from Web Browsers
MalwareRedLeaves

RedLeaves can gather browser usernames and passwords.

T1555.003
Credentials from Web Browsers
MalwareInvisibleFerret

InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data.

T1555.003
Credentials from Web Browsers
MalwareRainyDay

RainyDay can use tools to collect credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwareNETWIRE

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.

T1555.003
Credentials from Web Browsers
MalwareOLDBAIT

OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora.

T1555.003
Credentials from Web Browsers
MalwareCosmicDuke

CosmicDuke collects user credentials, including passwords, for various programs including Web browsers.

T1555.003
Credentials from Web Browsers
MalwareMirrorStealer

MirrorStealer can steal credentials stored in browsers.

T1555.003
Credentials from Web Browsers
MalwareEmotet

Emotet has been observed dropping browser password grabber modules.

T1555.003
Credentials from Web Browsers
MalwareOlympic Destroyer

Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers.

T1555.003
Credentials from Web Browsers
MalwareCrimson

Crimson contains a module to steal credentials from Web browsers on the victim machine.

T1555.003
Credentials from Web Browsers
MalwareMachete

Machete collects stored credentials from several web browsers.

T1555.003
Credentials from Web Browsers
MalwarePrikormka

A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers.

T1555.003
Credentials from Web Browsers
MalwareTRANSLATEXT

TRANSLATEXT has stolen credentials stored in Chrome.

T1555.003
Credentials from Web Browsers
MalwareMispadu

Mispadu can steal credentials from Google Chrome.

T1555.003
Credentials from Web Browsers
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.

T1555.003
Credentials from Web Browsers
MalwareXAgentOSX

XAgentOSX contains the getFirefoxPassword function to attempt to locate Firefox passwords.

T1555.003
Credentials from Web Browsers
MalwareKeyBoy

KeyBoy attempts to collect passwords from browsers.

T1555.003
Credentials from Web Browsers
MalwareBeaverTail

BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration.

T1555.003
Credentials from Web Browsers
MalwareROKRAT

ROKRAT can steal credentials stored in Web browsers by querying the sqlite database.

T1555.003
Credentials from Web Browsers
MalwareJavali

Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge.

T1555.003
Credentials from Web Browsers
MalwareLumma Stealer

Lumma Stealer has gathered credential and other information from multiple browsers.

T1555.003
Credentials from Web Browsers
MalwareTSCookie

TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers.

T1555.003
Credentials from Web Browsers
MalwareChaes

Chaes can steal login credentials and stored financial information from the browser.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.