ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1552.001×

23 examples

TechniqueUsed byProcedure example
T1552.001
Credentials In Files
MalwareTrickBot

TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials.

T1552.001
Credentials In Files
MalwareSmoke Loader

Smoke Loader searches for files named logins.json to parse for credentials.

T1552.001
Credentials In Files
MalwareEmotet

Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user.

T1552.001
Credentials In Files
MalwareHildegard

Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens.

T1552.001
Credentials In Files
MalwareBlackEnergy

BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store.

T1552.001
Credentials In Files
MalwareXTunnel

XTunnel is capable of accessing locally stored passwords on victims.

T1552.001
Credentials In Files
Malwarepngdowner

If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access.

T1552.001
Credentials In Files
MalwareStrelaStealer

StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application.

T1552.001
Credentials In Files
MalwarePysa

Pysa has extracted credentials from the password database before encrypting the files.

T1552.001
Credentials In Files
MalwareShai-Hulud

Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files.

T1552.001
Credentials In Files
MalwareAgent Tesla

Agent Tesla has the ability to extract credentials from configuration or support files.

T1552.001
Credentials In Files
MalwarejRAT

jRAT can capture passwords from common chat applications such as MSN Messenger, AOL, Instant Messenger, and and Google Talk.

T1552.001
Credentials In Files
MalwareAzorult

Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam.

T1552.001
Credentials In Files
ToolAADInternals

AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine.

T1552.001
Credentials In Files
ToolEmpire

Empire can use various modules to search for files containing passwords.

T1552.001
Credentials In Files
ToolPoshC2

PoshC2 contains modules for searching for passwords in local and remote files.

T1552.001
Credentials In Files
ToolTruffleHog

TruffleHog has obtained credentials stored in config files and credential files in victim environments.

T1552.001
Credentials In Files
ToolLaZagne

LaZagne can obtain credentials from chats, databases, mail, and WiFi.

T1552.001
Credentials In Files
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1552.001
Credentials In Files
ToolQuasarRAT

QuasarRAT can obtain passwords from FTP clients.

T1552.001
Credentials In Files
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments.

T1552.001
Credentials In Files
MalwareMini Shai-Hulud

Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json.

T1552.001
Credentials In Files
MalwareKali365

Kali365 has searched compromised mailboxes for credential material such as seed phrases and API keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.