Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.003 Credentials from Web Browsers |
GroupAPT3 | APT3 has used tools to dump passwords from browsers. |
| T1555.003 Credentials from Web Browsers |
GroupKimsuky | Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims. |
| T1555.003 Credentials from Web Browsers |
GroupVolt Typhoon | Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials. |
| T1555.003 Credentials from Web Browsers |
GroupPatchwork | Patchwork dumped the login data database from |
| T1555.003 Credentials from Web Browsers |
GroupAPT41 | APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores. |
| T1555.003 Credentials from Web Browsers |
GroupMuddyWater | MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupLeafminer | Leafminer used several tools for retrieving login and password information, including LaZagne. |
| T1555.003 Credentials from Web Browsers |
GroupSandworm Team | Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers. |
| T1555.003 Credentials from Web Browsers |
GroupZIRCONIUM | ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAPT37 | APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers. |
| T1555.003 Credentials from Web Browsers |
GroupOilRig | OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers. |
| T1555.003 Credentials from Web Browsers |
GroupTA505 | TA505 has used malware to gather credentials from Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
GroupRedCurl | |
| T1555.003 Credentials from Web Browsers |
GroupStealth Falcon | Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupMalteiro | Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView. |
| T1555.003 Credentials from Web Browsers |
GroupAPT42 | APT42 has used custom malware to steal credentials. |
| T1555.003 Credentials from Web Browsers |
GroupLAPSUS$ | LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer. |
| T1555.003 Credentials from Web Browsers |
GroupMolerats | Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims. |
| T1555.003 Credentials from Web Browsers |
GroupInception | Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex. |
| T1555.003 Credentials from Web Browsers |
GroupHEXANE | HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
GroupAjax Security Team | Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage. |
| T1555.003 Credentials from Web Browsers |
GroupAPT33 | APT33 has used a variety of publicly available tools like LaZagne to gather credentials. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.