Real-world descriptions of how a group, tool or campaign used a technique.
23 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1552.001 Credentials In Files |
MalwareTrickBot | TrickBot can obtain passwords stored in files from several applications such as Outlook, Filezilla, OpenSSH, OpenVPN and WinSCP. Additionally, it searches for the ".vnc.lnk" affix to steal VNC credentials. |
| T1552.001 Credentials In Files |
MalwareSmoke Loader | Smoke Loader searches for files named logins.json to parse for credentials. |
| T1552.001 Credentials In Files |
MalwareEmotet | Emotet has been observed leveraging a module that retrieves passwords stored on a system for the current logged-on user. |
| T1552.001 Credentials In Files |
MalwareHildegard | Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens. |
| T1552.001 Credentials In Files |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials stored in files on the host by various software programs, including The Bat! email client, Outlook, and Windows Credential Store. |
| T1552.001 Credentials In Files |
MalwareXTunnel | XTunnel is capable of accessing locally stored passwords on victims. |
| T1552.001 Credentials In Files |
Malwarepngdowner | If an initial connectivity check fails, pngdowner attempts to extract proxy details and credentials from Windows Protected Storage and from the IE Credentials Store. This allows the adversary to use the proxy credentials for subsequent requests if they enable outbound HTTP access. |
| T1552.001 Credentials In Files |
MalwareStrelaStealer | StrelaStealer searches for and if found collects the contents of files such as `logins.json` and `key4.db` in the `$APPDATA%\Thunderbird\Profiles\` directory, associated with the Thunderbird email application. |
| T1552.001 Credentials In Files |
MalwarePysa | Pysa has extracted credentials from the password database before encrypting the files. |
| T1552.001 Credentials In Files |
MalwareShai-Hulud | Shai-Hulud has gathered sensitive data stored in the Node.JS file `process.env` to include credentials and API keys. Shai-Hulud has harvested credentials stored in config files and credential files in victim environments to include `~/.aws/credentials`, `application_default_credentials.json`, and `azureProfile.json`. Shai-Hulud has also targeted credentials and tokens stored in NPM files `.npmrc` and GitHub config files. |
| T1552.001 Credentials In Files |
MalwareAgent Tesla | Agent Tesla has the ability to extract credentials from configuration or support files. |
| T1552.001 Credentials In Files |
MalwarejRAT | jRAT can capture passwords from common chat applications such as MSN Messenger, AOL, Instant Messenger, and and Google Talk. |
| T1552.001 Credentials In Files |
MalwareAzorult | Azorult can steal credentials in files belonging to common software such as Skype, Telegram, and Steam. |
| T1552.001 Credentials In Files |
ToolAADInternals | AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine. |
| T1552.001 Credentials In Files |
ToolEmpire | Empire can use various modules to search for files containing passwords. |
| T1552.001 Credentials In Files |
ToolPoshC2 | PoshC2 contains modules for searching for passwords in local and remote files. |
| T1552.001 Credentials In Files |
ToolTruffleHog | TruffleHog has obtained credentials stored in config files and credential files in victim environments. |
| T1552.001 Credentials In Files |
ToolLaZagne | LaZagne can obtain credentials from chats, databases, mail, and WiFi. |
| T1552.001 Credentials In Files |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1552.001 Credentials In Files |
ToolQuasarRAT | QuasarRAT can obtain passwords from FTP clients. |
| T1552.001 Credentials In Files |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has the ability to check over 50 file paths for credentials stored in files across CI/CD, cloud, container, and other environments. |
| T1552.001 Credentials In Files |
MalwareMini Shai-Hulud | Mini Shai-Hulud has collected credentials stored within configuration files. Mini Shai-Hulud has also gathered credentials from files stored in common credential file paths to include targeting git-credentials, azureProfile.json, and application_default_credentials.json. |
| T1552.001 Credentials In Files |
MalwareKali365 | Kali365 has searched compromised mailboxes for credential material such as seed phrases and API keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.