Credentials from Password Stores: Credentials from Web Browsers, Sub-technique T1555.003 - Enterprise (original) (raw)

S0331

Agent Tesla

Agent Tesla can gather credentials from a number of browsers.[6]

G0130

Ajax Security Team

Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage.[7]

G0022

APT3

APT3 has used tools to dump passwords from browsers.[8]

G0064

APT33

APT33 has used a variety of publicly available tools like LaZagne to gather credentials.[9][10]

G0067

APT37

APT37 has used a credential stealer known as ZUMKONG that can harvest usernames and passwords stored in browsers.[11]

G0096

APT41

APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores.[12]

G1044

APT42

APT42 has used custom malware to steal credentials.[13]

S0344

Azorult

Azorult can steal credentials from the victim's browser.[14]

S0093

Backdoor.Oldrea

Some Backdoor.Oldrea samples contain a publicly available Web browser password recovery tool.[15]

S1246

BeaverTail

BeaverTail has stolen passwords saved in web browsers.[16][17][18][19] BeaverTail has also been known to collect login data from Firefox within key3.db, key4.db and logins.json from /.mozilla/firefox/ for exfiltration.[20]

S0089

BlackEnergy

BlackEnergy has used a plug-in to gather credentials from web browsers including FireFox, Google Chrome, and Internet Explorer.[21][22]

S0657

BLUELIGHT

BLUELIGHT can collect passwords stored in web browers, including Internet Explorer, Edge, Chrome, and Naver Whale.[23]

S0484

Carberp

Carberp's passw.plug plugin can gather passwords saved in Opera, Internet Explorer, Safari, Firefox, and Chrome.[24]

S0631

Chaes

Chaes can steal login credentials and stored financial information from the browser.[25]

S0144

ChChes

ChChes steals credentials stored inside Internet Explorer.[26]

S0492

CookieMiner

CookieMiner can steal saved usernames and passwords in Chrome as well as credit card credentials.[27]

S0050

CosmicDuke

CosmicDuke collects user credentials, including passwords, for various programs including Web browsers.[28]

S0115

Crimson

Crimson contains a module to steal credentials from Web browsers on the victim machine.[29][30]

S0367

Emotet

Emotet has been observed dropping browser password grabber modules. [31][32]

S0363

Empire

Empire can use modules that extract passwords from common web browsers such as Firefox and Chrome.[33]

G0037

FIN6

FIN6 has used the Stealer One credential stealer to target web browsers.[34]

S9010

GlassWorm

GlassWorm has gathered credentials stored in Mozilla FireFox and Chromium-based Browsers.[35][36]

S0531

Grandoreiro

Grandoreiro can steal cookie data and credentials from Google Chrome.[37][38]

S0132

H1N1

H1N1 dumps usernames and passwords from Firefox, Internet Explorer, and Outlook.[39]

G1001

HEXANE

HEXANE has used a Mimikatz-based tool and a PowerShell script to steal passwords from Google Chrome.[40]

S0434

Imminent Monitor

Imminent Monitor has a PasswordRecoveryPacket module for recovering browser passwords.[41]

G0100

Inception

Inception used a browser plugin to steal passwords and sessions from Internet Explorer, Chrome, Opera, Firefox, Torch, and Yandex.[42]

S1245

InvisibleFerret

InvisibleFerret has stolen login data, autofill data, cryptocurrency wallets, and payment information saved in web browsers such as Chrome, Brave, Opera, Yandex and Edge, to include versions affiliated with major operating systems on Windows, Linux, and macOS.[16][20] InvisibleFerret has also leveraged the command ssh_zcp to copy browser data to include extensions and cryptocurrency wallet data.[43]

S0528

Javali

Javali can capture login credentials from open browsers including Firefox, Chrome, Internet Explorer, and Edge.[44]

S0283

jRAT

jRAT can capture passwords from common web browsers such as Internet Explorer, Google Chrome, and Firefox.[45]

C0044

Juicy Mix

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) to collect credentials.[46]

S0387

KeyBoy

KeyBoy attempts to collect passwords from browsers.[47]

S0526

KGH_SPY

KGH_SPY has the ability to steal data from the Chrome, Edge, Firefox, Thunderbird, and Opera browsers.[48]

G0094

Kimsuky

Kimsuky has used browser extensions including Google Chrome to steal passwords and cookies from browsers. Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.[49][50][51][52]

S0356

KONNI

KONNI can steal profiles (containing credential information) from Firefox, Chrome, and Opera.[53]

G1004

LAPSUS$

LAPSUS$ has obtained passwords and session tokens with the use of the Redline password stealer.[54]

S0349

LaZagne

LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.[55]

G0077

Leafminer

Leafminer used several tools for retrieving login and password information, including LaZagne.[56]

S0681

Lizar

Lizar has a module to collect usernames and passwords stored in browsers.[57]

S0447

Lokibot

Lokibot has demonstrated the ability to steal credentials from multiple applications and data sources including Safari and the Chromium and Mozilla Firefox-based web browsers.[58]

S1213

Lumma Stealer

Lumma Stealer has gathered credential and other information from multiple browsers.[59][60][61]

S0409

Machete

Machete collects stored credentials from several web browsers.[62]

G1026

Malteiro

Malteiro has stolen credentials stored in the victim’s browsers via software tool NirSoft WebBrowserPassView.[63]

S1156

Manjusaka

Manjusaka gathers credentials from Chromium-based browsers.[64]

S0530

Melcoz

Melcoz has the ability to steal credentials from web browsers.[44]

S1146

MgBot

MgBot includes modules for stealing credentials from various browsers and applications, including Chrome, Opera, Firefox, Foxmail, QQBrowser, FileZilla, and WinSCP.[65][66]

S0002

Mimikatz

Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.[67][68][69][70]

S9022

MirrorStealer

MirrorStealer can steal credentials stored in browsers.[71][72]

S1122

Mispadu

Mispadu can steal credentials from Google Chrome.[63][73][74]

G0021

Molerats

Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.[75]

G0069

MuddyWater

MuddyWater has run tools including Browser64 to steal passwords saved in victim web browsers.[76][77]

S0198

NETWIRE

NETWIRE has the ability to steal credentials from web browsers including Internet Explorer, Opera, Yandex, and Chrome.[78][79][80]

S0385

njRAT

njRAT has a module that steals passwords saved in victim web browsers.[81][82][83]

G0049

OilRig

OilRig has used credential dumping tools such as LaZagne to steal credentials to accounts logged into the compromised system and to Outlook Web Access.[84][85][86][87] OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.[87]

S0138

OLDBAIT

OLDBAIT collects credentials from Internet Explorer, Mozilla Firefox, and Eudora.[88]

S0365

Olympic Destroyer

Olympic Destroyer contains a module that tries to obtain stored credentials from web browsers.[1]

G0040

Patchwork

Patchwork dumped the login data database from \AppData\Local\Google\Chrome\User Data\Default\Login Data.[89]

S0048

PinchDuke

PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with many sources such as Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, and Internet Explorer. [28]

S0435

PLEAD

PLEAD can harvest saved credentials from browsers such as Google Chrome, Microsoft Internet Explorer, and Mozilla Firefox.[90][91]

S0428

PoetRAT

PoetRAT has used a Python tool named Browdec.exe to steal browser credentials.[92]

S0113

Prikormka

A module in Prikormka gathers logins and passwords stored in applications on the victims, including Google Chrome, Mozilla Firefox, and several other browsers.[93]

S0279

Proton

Proton gathers credentials for Google Chrome.[94]

S0192

Pupy

Pupy can use Lazagne for harvesting credentials.[95]

S0650

QakBot

QakBot has collected usernames and passwords from Firefox and Chrome.[96]

S0262

QuasarRAT

QuasarRAT can obtain passwords from common web browsers.[97][98][99]

S1148

Raccoon Stealer

Raccoon Stealer collects passwords, cookies, and autocomplete information from various popular web browsers.[100]

S0629

RainyDay

RainyDay can use tools to collect credentials from web browsers.[101]

G1039

RedCurl

RedCurl used LaZagne to obtain passwords from web browsers.[102][103]

S0153

RedLeaves

RedLeaves can gather browser usernames and passwords.[104]

S1240

RedLine Stealer

RedLine Stealer was designed to steal sensitive information from web browsers, including credit card details, saved credentials, and autocomplete data.[105] RedLine Stealer can also gather credentials from several browsers.[106][107][108]

S0240

ROKRAT

ROKRAT can steal credentials stored in Web browsers by querying the sqlite database.[109]

G0034

Sandworm Team

Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers.[110]

S0692

SILENTTRINITY

SILENTTRINITY can collect clear text web credentials for Internet Explorer/Edge.[111]

S0226

Smoke Loader

Smoke Loader searches for credentials stored from web browsers.[112]

C0024

SolarWinds Compromise

During the SolarWinds Compromise, APT29 stole users' saved passwords from Chrome.[113]

G0038

Stealth Falcon

Stealth Falcon malware gathers passwords from multiple sources, including Internet Explorer, Firefox, and Chrome.[114]

S1042

SUGARDUMP

SUGARDUMP variants have harvested credentials from browsers such as Firefox, Chrome, Opera, and Edge.[115]

G0092

TA505

TA505 has used malware to gather credentials from Internet Explorer.[116]

S1201

TRANSLATEXT

TRANSLATEXT has stolen credentials stored in Chrome.[117]

S0266

TrickBot

TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge, sometimes using esentutl.[118][119][120]

S0094

Trojan.Karagany

Trojan.Karagany can steal data and credentials from browsers.[121]

S0436

TSCookie

TSCookie has the ability to steal saved passwords from the Internet Explorer, Edge, Firefox, and Chrome browsers.[122]

S0130

Unknown Logger

Unknown Logger is capable of stealing usernames and passwords from browsers on the victim machine.[123]

G1017

Volt Typhoon

Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials.[124]

S0670

WarzoneRAT

WarzoneRAT has the capability to grab passwords from numerous web browsers as well as from Outlook and Thunderbird email clients.[125][126]

S0161

XAgentOSX

XAgentOSX contains the getFirefoxPassword function to attempt to locate Firefox passwords.[127]

S1207

XLoader

XLoader can gather credentials from several web browsers.[128][129][130]

S0251

Zebrocy

Zebrocy has the capability to upload dumper tools that extract credentials from web browsers and store them in database files.[131]

G0128

ZIRCONIUM

ZIRCONIUM has used a tool to steal credentials from installed web browsers including Microsoft Internet Explorer and Google Chrome.[132]