ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1555.001×

11 examples

TechniqueUsed byProcedure example
T1555.001
Keychain
MalwareiKitten

iKitten collects the keychains on the system.

T1555.001
Keychain
MalwareCuckoo Stealer

Cuckoo Stealer can capture files from a targeted user's keychain directory.

T1555.001
Keychain
MalwareGreen Lambert

Green Lambert can use Keychain Services API functions to find and collect passwords, such as `SecKeychainFindInternetPassword` and `SecKeychainItemCopyAttributesAndData`.

T1555.001
Keychain
MalwareLightSpy

LightSpy performs an in-memory keychain query via `SecItemCopyMatching()` then formats the retrieved data as a JSON blob for exfiltration.

T1555.001
Keychain
MalwareBeaverTail

BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`.

T1555.001
Keychain
MalwareGlassWorm

GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`.

T1555.001
Keychain
MalwareCalisto

Calisto collects Keychain storage data and copies those passwords/tokens to a file.

T1555.001
Keychain
MalwareMacMa

MacMa can dump credentials from the macOS keychain.

T1555.001
Keychain
MalwareProton

Proton gathers credentials in files for keychains.

T1555.001
Keychain
ToolEmpire

Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential.

T1555.001
Keychain
ToolLaZagne

LaZagne can obtain credentials from macOS Keychains.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.