ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1555.003×

23 examples

TechniqueUsed byProcedure example
T1555.003
Credentials from Web Browsers
GroupAPT3

APT3 has used tools to dump passwords from browsers.

T1555.003
Credentials from Web Browsers
GroupKimsuky

Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.

T1555.003
Credentials from Web Browsers
GroupVolt Typhoon

Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials.

T1555.003
Credentials from Web Browsers
GroupPatchwork

Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data.

T1555.003
Credentials from Web Browsers
GroupAPT41

APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.

T1555.003
Credentials from Web Browsers
GroupMuddyWater

MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.

T1555.003
Credentials from Web Browsers
GroupFIN6

FIN6 has used the Stealer One credential stealer to target web browsers.

T1555.003
Credentials from Web Browsers
GroupLeafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.

T1555.003
Credentials from Web Browsers
GroupSandworm Team

Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers.

T1555.003
Credentials from Web Browsers
GroupZIRCONIUM

ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome.

T1555.003
Credentials from Web Browsers
GroupAPT37

APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers.

T1555.003
Credentials from Web Browsers
GroupOilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access. OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.

T1555.003
Credentials from Web Browsers
GroupTA505

TA505 has used malware to gather credentials from Internet Explorer.

T1555.003
Credentials from Web Browsers
GroupRedCurl

RedCurl used LaZagne to obtain passwords from web browsers.

T1555.003
Credentials from Web Browsers
GroupStealth Falcon

Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome.

T1555.003
Credentials from Web Browsers
GroupMalteiro

Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView.

T1555.003
Credentials from Web Browsers
GroupAPT42

APT42 has used custom malware to steal credentials.

T1555.003
Credentials from Web Browsers
GroupLAPSUS$

LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer.

T1555.003
Credentials from Web Browsers
GroupMolerats

Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.

T1555.003
Credentials from Web Browsers
GroupInception

Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex.

T1555.003
Credentials from Web Browsers
GroupHEXANE

HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome.

T1555.003
Credentials from Web Browsers
GroupAjax Security Team

Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage.

T1555.003
Credentials from Web Browsers
GroupAPT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.