ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1555×

26 examples

TechniqueUsed byProcedure example
T1555
Credentials from Password Stores
MalwareMatryoshka

Matryoshka is capable of stealing Outlook passwords.

T1555
Credentials from Password Stores
MalwareNETWIRE

NETWIRE can retrieve passwords from messaging and mail client applications.

T1555
Credentials from Password Stores
MalwareOLDBAIT

OLDBAIT collects credentials from several email clients.

T1555
Credentials from Password Stores
MalwareCosmicDuke

CosmicDuke collects user credentials, including passwords, for various programs including popular instant messaging applications and email clients as well as WLAN keys.

T1555
Credentials from Password Stores
MalwareMirrorStealer

MirrorStealer has the ability to steal credentials from email clients.

T1555
Credentials from Password Stores
MalwarePrikormka

A module in Prikormka collects passwords stored in applications installed on the victim.

T1555
Credentials from Password Stores
MalwareMispadu

Mispadu has obtained credentials from mail clients via NirSoft MailPassView.

T1555
Credentials from Password Stores
MalwareBeaverTail

BeaverTail has collected keys stored for Solana stored in `.config/solana/id.json` and other login details associated with macOS within `/Library/Keychains/login.keychain` or for Linux within `/.local/share/keyrings`.

T1555
Credentials from Password Stores
MalwareDarkGate

DarkGate use Nirsoft Network Password Recovery or NetPass tools to steal stored RDP credentials in some malware versions.

T1555
Credentials from Password Stores
MalwareKGH_SPY

KGH_SPY can collect credentials from WINSCP.

T1555
Credentials from Password Stores
MalwareRedLine Stealer

RedLine Stealer has obtained credentials from VPN services, FTP clients and Instant Messenger (IM)/Chat clients.

T1555
Credentials from Password Stores
MalwareXLoader

XLoader can collect credentials stored in email clients.

T1555
Credentials from Password Stores
MalwareMgBot

MgBot includes modules for stealing stored credentials from Outlook and Foxmail email client software.

T1555
Credentials from Password Stores
MalwarePinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as The Bat!, Yahoo!, Mail.ru, Passport.Net, Google Talk, and Microsoft Outlook.

T1555
Credentials from Password Stores
MalwarePLEAD

PLEAD has the ability to steal saved passwords from Microsoft Outlook.

T1555
Credentials from Password Stores
MalwareCarberp

Carberp's passw.plug plugin can gather account information from multiple instant messaging, email, and social media services, as well as FTP, VNC, and VPN clients.

T1555
Credentials from Password Stores
MalwareLokibot

Lokibot has stolen credentials from multiple applications and data sources including Windows OS credentials, email clients, FTP, and SFTP clients.

T1555
Credentials from Password Stores
MalwareManjusaka

Manjusaka extracts credentials from the Windows Registry associated with Premiumsoft Navicat, a utility used to facilitate access to various database types.

T1555
Credentials from Password Stores
MalwareAgent Tesla

Agent Tesla has the ability to steal credentials from FTP clients and wireless profiles.

T1555
Credentials from Password Stores
MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

T1555
Credentials from Password Stores
ToolPoshC2

PoshC2 can decrypt passwords stored in the RDCMan configuration file.

T1555
Credentials from Password Stores
ToolMimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from the credential vault and DPAPI.

T1555
Credentials from Password Stores
ToolLaZagne

LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms.

T1555
Credentials from Password Stores
ToolPupy

Pupy can use Lazagne for harvesting credentials.

T1555
Credentials from Password Stores
ToolQuasarRAT

QuasarRAT can obtain passwords from common FTP clients.

T1555
Credentials from Password Stores
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can harvest credentials from cryptocurrency wallets and keystores such as Ethereum keystores, Cardano keys, Solana validator keypairs, Ledger device files, and Anchor deploy keys.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.