Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1552.001 Credentials In Files |
GroupIndrik Spider | Indrik Spider has searched files to obtain and exfiltrate credentials. |
| T1552.001 Credentials In Files |
GroupAPT3 | APT3 has a tool that can locate credentials in files on the file system such as those from Firefox or Chrome. |
| T1552.001 Credentials In Files |
GroupKimsuky | Kimsuky has used tools that are capable of obtaining credentials from saved mail. |
| T1552.001 Credentials In Files |
GroupMuddyWater | MuddyWater has run a tool that steals passwords saved in victim email. |
| T1552.001 Credentials In Files |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1552.001 Credentials In Files |
GroupTeamTNT | TeamTNT has searched for unsecured AWS credentials and Docker API credentials. |
| T1552.001 Credentials In Files |
GroupScattered Spider | Scattered Spider Spider searches for credential storage documentation on a compromised host. |
| T1552.001 Credentials In Files |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. |
| T1552.001 Credentials In Files |
GroupTA505 | TA505 has used malware to gather credentials from FTP clients and Outlook. |
| T1552.001 Credentials In Files |
GroupRedCurl | |
| T1552.001 Credentials In Files |
GroupEmber Bear | Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials. |
| T1552.001 Credentials In Files |
GroupFox Kitten | Fox Kitten has accessed files to gain valid credentials. |
| T1552.001 Credentials In Files |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
| T1552.001 Credentials In Files |
GroupFIN13 | FIN13 has obtained administrative credentials by browsing through local files on a compromised machine. |
| T1552.001 Credentials In Files |
GroupShinyHunters | ShinyHunters has gathered PII from database infrastructure. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.