Password Managers

T1555.005

Sub-technique of T1555 Credentials from Password Stores.View on attack.mitre.org

About this technique

Adversaries may acquire user credentials from third-party password managers. Password managers are applications designed to store user credentials, normally in an encrypted database. Credentials are typically accessible after a user provides a master password that unlocks the database. After the database is unlocked, these credentials may be copied to memory. These databases can be stored as files on disk.

Adversaries may acquire user credentials from password managers by extracting the master password and/or plain-text credentials from memory. Adversaries may extract credentials from memory via Exploitation for Credential Access.
Adversaries may also try brute forcing via Password Guessing to obtain the master password of a password manager.

Detection rules4

Rules on DetectionCode tagged with T1555.005.

Sigma1

RuleLevelLog source
Remote Thread Created In KeePass.EXEhighwindows / create_remote_thread

Splunk3

RuleTypeRiskData source
Linux Auditd Find Credentials From Password ManagersTTPNULLLinux Auditd Execve
Linux Auditd Find Credentials From Password StoresTTPNULLLinux Auditd Execve
Windows Password Managers DiscoveryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups7

Software5

Campaigns1

Procedure examples13

Groups7

Used byProcedure example
GroupFox Kitten

Fox Kitten has used scripts to access credential information from the KeePass database.

GroupIndrik Spider

Indrik Spider has accessed and exported passwords from password managers.

GroupLAPSUS$

LAPSUS$ has accessed local password managers and databases to obtain further credentials from a compromised network.

GroupScattered Spider

Scattered Spider has searched for credentials in password vaults and Privileged Access Management (PAM) solutions including HashiCorp Vault.

GroupStorm-0501

Storm-0501 has stolen credentials contained in the password manager Keepass by utilizing Find-KeePassConfig.ps1.

GroupThreat Group-3390

Threat Group-3390 obtained a KeePass database from a compromised host.

GroupUNC3886

UNC3886 has targeted KeyPass password database files for credential access.

Software5

Used byProcedure example
MalwareInvisibleFerret

InvisibleFerret has utilized the command `ssh_zcp` to exfiltrate data from browser extensions and password managers via Telegram and FTP.

MalwareMarkiRAT

MarkiRAT can gather information from the Keepass password manager.

MalwareMini Shai-Hulud

Mini Shai-Hulud has gathered credentials stored in password managers to include password vaults.

MalwareProton

Proton gathers credentials in files for 1password.

MalwareTrickBot

TrickBot can steal passwords from the KeePass open source password manager.

Campaigns1

Used byProcedure example
CampaignOperation Wocao

During Operation Wocao, threat actors accessed and collected credentials from password managers.

References5

  1. Cyberreason Anchor December 2019 Open source
    Dahan, A. et al. (2019, December 11). DROPPING ANCHOR: FROM A TRICKBOT INFECTION TO THE DISCOVERY OF THE ANCHOR MALWARE. Retrieved September 10, 2020.
  2. FoxIT Wocao December 2019 Open source
    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.
  3. Github KeeThief Open source
    Lee, C., Schoreder, W. (n.d.). KeeThief. Retrieved February 8, 2021.
  4. NVD CVE-2019-3610 Open source
    National Vulnerability Database. (2019, October 9). CVE-2019-3610 Detail. Retrieved April 14, 2021.
  5. ise Password Manager February 2019 Open source
    ise. (2019, February 19). Password Managers: Under the Hood of Secrets Management. Retrieved January 22, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.