Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1217 Browser Information Discovery |
MalwareMachete | Machete retrieves the user profile data (e.g., browsers) from Chrome and Firefox browsers. |
| T1217 Browser Information Discovery |
MalwarePowerLess | PowerLess has a browser info stealer module that can read Chrome and Edge browser database files. |
| T1217 Browser Information Discovery |
MalwareMafalda | Mafalda can collect the contents of the `%USERPROFILE%\AppData\Local\Google\Chrome\User Data\LocalState` file. |
| T1217 Browser Information Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can collect bookmarks, cookies, and history from Safari. |
| T1217 Browser Information Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server victim browser bookmarks. |
| T1217 Browser Information Discovery |
MalwareMispadu | Mispadu can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1217 Browser Information Discovery |
MalwareLightSpy | To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist` file. It also utilizes Apple's `CWWiFiClient` API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values. |
| T1217 Browser Information Discovery |
MalwareBeaverTail | BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1217 Browser Information Discovery |
MalwareDarkWatchman | DarkWatchman can retrieve browser history. |
| T1217 Browser Information Discovery |
MalwareLumma Stealer | Lumma Stealer has identified and gathered information from two-factor authentication extensions for multiple browsers. |
| T1217 Browser Information Discovery |
MalwareGlassWorm | GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets. |
| T1217 Browser Information Discovery |
MalwareRedLine Stealer | RedLine Stealer can collect information from browsers and browser extensions. |
| T1217 Browser Information Discovery |
MalwareSUGARDUMP | SUGARDUMP has collected browser bookmark and history information. |
| T1217 Browser Information Discovery |
MalwareCalisto | Calisto collects information on bookmarks from Google Chrome. |
| T1217 Browser Information Discovery |
MalwareTroll Stealer | Troll Stealer collects information from Chromium-based browsers and Firefox such as cookies, history, downloads, and extensions. |
| T1217 Browser Information Discovery |
MalwareLizar | Lizar can retrieve browser history and database files. |
| T1217 Browser Information Discovery |
MalwareDtrack | Dtrack can retrieve browser history. |
| T1217 Browser Information Discovery |
ToolEmpire | Empire has the ability to gather browser data such as bookmarks and visited sites. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.