Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1553.005 Mark-of-the-Web Bypass |
GroupAPT38 | APT38 has used ISO and VHD files to deploy malware and to bypass Mark-of-the-Web (MOTW) security measures. |
| T1553.005 Mark-of-the-Web Bypass |
GroupTA505 | TA505 has used .iso files to deploy malicious .lnk files. |
| T1553.005 Mark-of-the-Web Bypass |
GroupAPT29 | APT29 has embedded ISO images and VHDX files in HTML to evade Mark-of-the-Web. |
| T1553.006 Code Signing Policy Modification |
GroupAPT39 | APT39 has used malware to turn off the |
| T1553.006 Code Signing Policy Modification |
GroupTurla | Turla has modified variables in kernel memory to turn off Driver Signature Enforcement after exploiting vulnerabilities that obtained kernel mode privileges. |
| T1554 Compromise Host Software Binary |
GroupUNC3886 | UNC3886 has trojanized Fortinet firmware and replaced the legitimate `/usr/bin/tac_plus` TACACS+ daemon for Linux with a malicious version containing credential logging functionality. |
| T1554 Compromise Host Software Binary |
GroupAPT5 | APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence. |
| T1555 Credentials from Password Stores |
GroupVolt Typhoon | Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY. |
| T1555 Credentials from Password Stores |
GroupAPT41 | APT41 has obtained information about accounts, lists of employees, and plaintext and hashed passwords from databases. |
| T1555 Credentials from Password Stores |
GroupEvilnum | Evilnum can collect email credentials from victims. |
| T1555 Credentials from Password Stores |
GroupMuddyWater | MuddyWater has performed credential dumping with LaZagne and other tools, including by dumping passwords saved in victim email. |
| T1555 Credentials from Password Stores |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP. |
| T1555 Credentials from Password Stores |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1555 Credentials from Password Stores |
GroupAPT39 | APT39 has used the Smartftp Password Decryptor tool to decrypt FTP passwords. |
| T1555 Credentials from Password Stores |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1555 Credentials from Password Stores |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from multiple sources, including Windows Credential Vault and Outlook. |
| T1555 Credentials from Password Stores |
GroupMalteiro | Malteiro has obtained credentials from mail clients via NirSoft MailPassView. |
| T1555 Credentials from Password Stores |
GroupHEXANE | HEXANE has run `cmdkey` on victim machines to identify stored credentials. |
| T1555 Credentials from Password Stores |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1555.001 Keychain |
GroupContagious Interview | Contagious Interview has leveraged malware variants configured to dump credentials from the macOS keychain. |
| T1555.003 Credentials from Web Browsers |
GroupAPT3 | APT3 has used tools to dump passwords from browsers. |
| T1555.003 Credentials from Web Browsers |
GroupKimsuky | Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims. |
| T1555.003 Credentials from Web Browsers |
GroupVolt Typhoon | Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials. |
| T1555.003 Credentials from Web Browsers |
GroupPatchwork | Patchwork dumped the login data database from |
| T1555.003 Credentials from Web Browsers |
GroupAPT41 | APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores. |
| T1555.003 Credentials from Web Browsers |
GroupMuddyWater | MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1555.003 Credentials from Web Browsers |
GroupSandworm Team | Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers. |
| T1555.003 Credentials from Web Browsers |
GroupZIRCONIUM | ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAPT37 | APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers. |
| T1555.003 Credentials from Web Browsers |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupTA505 | TA505 has used malware to gather credentials from Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
GroupRedCurl | |
| T1555.003 Credentials from Web Browsers |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupMalteiro | Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView. |
| T1555.003 Credentials from Web Browsers |
GroupAPT42 | APT42 has used custom malware to steal credentials. |
| T1555.003 Credentials from Web Browsers |
GroupLAPSUS$ | LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer. |
| T1555.003 Credentials from Web Browsers |
GroupMolerats | Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims. |
| T1555.003 Credentials from Web Browsers |
GroupInception | Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex. |
| T1555.003 Credentials from Web Browsers |
GroupHEXANE | HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAjax Security Team | Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage. |
| T1555.003 Credentials from Web Browsers |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1555.004 Windows Credential Manager |
GroupOilRig | OilRig has used credential dumping tool named VALUEVAULT to steal credentials from the Windows Credential Manager. |
| T1555.004 Windows Credential Manager |
GroupTurla | Turla has gathered credentials from the Windows Credential Manager tool. |
| T1555.004 Windows Credential Manager |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from the Windows Credential Vault. |
| T1555.004 Windows Credential Manager |
GroupWizard Spider | Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network. |
| T1555.005 Password Managers |
GroupIndrik Spider | Indrik Spider has accessed and exported passwords from password managers. |
| T1555.005 Password Managers |
GroupScattered Spider | Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault. |
| T1555.005 Password Managers |
GroupUNC3886 | UNC3886 has targeted KeyPass password database files for credential access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.