Technique with 8 sub-techniques.View on attack.mitre.org
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Rules on DetectionCode tagged with T1552 or one of its sub-techniques.
| Used by | Procedure example |
|---|---|
| GroupVolt Typhoon | Volt Typhoon has obtained credentials insecurely stored on targeted network appliances. |
| Used by | Procedure example |
|---|---|
| MalwareAstaroth | Astaroth uses an external software known as NetPass to recover passwords. |
| MalwareDarkGate | DarkGate uses NirSoft tools to steal user credentials from the infected machine. NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe. |
| ToolNPPSPY | NPPSPY captures credentials by recording them through an alternative network listener registered to the |
| ToolPacu | Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates. |
| Used by | Procedure example |
|---|---|
| CampaignLeviathan Australian Intrusions | Leviathan gathered credentials hardcoded in binaries located on victim devices during Leviathan Australian Intrusions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.