Real-world descriptions of how a group, tool or campaign used a technique.
64 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1555.003 Credentials from Web Browsers |
MalwareTrickBot | TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl. |
| T1555.003 Credentials from Web Browsers |
MalwareBackdoor.Oldrea | Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool. |
| T1555.003 Credentials from Web Browsers |
MalwareSmoke Loader | Smoke Loader searches for credentials stored from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLeaves | RedLeaves can gather browser usernames and passwords. |
| T1555.003 Credentials from Web Browsers |
MalwareInvisibleFerret | InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS. InvisibleFerret has also leveraged the command `ssh_zcp` to copy browser data to include extensions and cryptocurrency wallet data. |
| T1555.003 Credentials from Web Browsers |
MalwareRainyDay | RainyDay can use tools to collect credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareNETWIRE | NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareOLDBAIT | OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora. |
| T1555.003 Credentials from Web Browsers |
MalwareCosmicDuke | CosmicDuke collects user credentials, including passwords, for various programs including Web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareMirrorStealer | MirrorStealer can steal credentials stored in browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareEmotet | Emotet has been observed dropping browser password grabber modules. |
| T1555.003 Credentials from Web Browsers |
MalwareOlympic Destroyer | Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareCrimson | Crimson contains a module to steal credentials from Web browsers on the victim machine. |
| T1555.003 Credentials from Web Browsers |
MalwareMachete | Machete collects stored credentials from several web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarePrikormka | A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTRANSLATEXT | TRANSLATEXT has stolen credentials stored in Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareMispadu | Mispadu can steal credentials from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareBlackEnergy | BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwareXAgentOSX | XAgentOSX contains the getFirefoxPassword function to attempt to locate Firefox passwords. |
| T1555.003 Credentials from Web Browsers |
MalwareKeyBoy | KeyBoy attempts to collect passwords from browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareBeaverTail | BeaverTail has stolen passwords saved in web browsers. BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from `/.mozilla/firefox/` for exfiltration. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| T1555.003 Credentials from Web Browsers |
MalwareROKRAT | ROKRAT can steal credentials stored in Web browsers by querying the sqlite database. |
| T1555.003 Credentials from Web Browsers |
MalwareJavali | Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge. |
| T1555.003 Credentials from Web Browsers |
MalwareLumma Stealer | Lumma Stealer has gathered credential and other information from multiple browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTSCookie | TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareChaes | Chaes can steal login credentials and stored financial information from the browser. |
| T1555.003 Credentials from Web Browsers |
MalwareGlassWorm | GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareTrojan.Karagany | Trojan.Karagany can steal data and credentials from browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareKONNI | KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera. |
| T1555.003 Credentials from Web Browsers |
MalwareBLUELIGHT | BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale. |
| T1555.003 Credentials from Web Browsers |
MalwareKGH_SPY | KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareRedLine Stealer | RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data. RedLine Stealer can also gather credentials from several browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareGrandoreiro | Grandoreiro can steal cookie data and credentials from Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareSUGARDUMP | SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge. |
| T1555.003 Credentials from Web Browsers |
MalwareXLoader | XLoader can gather credentials from several web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareMgBot | MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP. |
| T1555.003 Credentials from Web Browsers |
MalwareZebrocy | Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files. |
| T1555.003 Credentials from Web Browsers |
MalwareUnknown Logger | Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine. |
| T1555.003 Credentials from Web Browsers |
MalwarePinchDuke | PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwarePLEAD | PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox. |
| T1555.003 Credentials from Web Browsers |
MalwareRaccoon Stealer | Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareCarberp | Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareProton | Proton gathers credentials for Google Chrome. |
| T1555.003 Credentials from Web Browsers |
MalwareLokibot | Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarePoetRAT | PoetRAT has used a Python tool named Browdec.exe to steal browser credentials. |
| T1555.003 Credentials from Web Browsers |
MalwareMelcoz | Melcoz has the ability to steal credentials from web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwarenjRAT | njRAT has a module that steals passwords saved in victim web browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareChChes | ChChes steals credentials stored inside Internet Explorer. |
| T1555.003 Credentials from Web Browsers |
MalwareManjusaka | Manjusaka gathers credentials from Chromium-based browsers. |
| T1555.003 Credentials from Web Browsers |
MalwareAgent Tesla | Agent Tesla can gather credentials from a number of browsers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.