Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.001 Keychain |
MalwareiKitten | iKitten collects the keychains on the system. |
| T1555.001 Keychain |
MalwareCuckoo Stealer | Cuckoo Stealer can capture files from a targeted user's keychain directory. |
| T1555.001 Keychain |
MalwareGreen Lambert | Green Lambert can use Keychain Services API functions to find and collect passwords, such as `SecKeychainFindInternetPassword` and `SecKeychainItemCopyAttributesAndData`. |
| T1555.001 Keychain |
MalwareLightSpy | LightSpy performs an in-memory keychain query via `SecItemCopyMatching()` then formats the retrieved data as a JSON blob for exfiltration. |
| T1555.001 Keychain |
MalwareBeaverTail | BeaverTail has collected keys associated with macOS within `/Library/Keychains/login.keychain`. |
| T1555.001 Keychain |
MalwareGlassWorm | GlassWorm has collected keys stored within `/Library/Keychains/login.keychain-db`. |
| T1555.001 Keychain |
MalwareCalisto | Calisto collects Keychain storage data and copies those passwords/tokens to a file. |
| T1555.001 Keychain |
MalwareMacMa | MacMa can dump credentials from the macOS keychain. |
| T1555.001 Keychain |
MalwareProton | Proton gathers credentials in files for keychains. |
| T1555.001 Keychain |
ToolEmpire | Empire uses the command `/usr/bin/security dump-keychain -d` to read the keychain credential. |
| T1555.001 Keychain |
ToolLaZagne | LaZagne can obtain credentials from macOS Keychains. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.