FORENSIA

ATT&CK · T1555.003 · sub-technique

Credentials from Web Browsers

Tactics: credential-access

About

Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store; however, methods exist to extract plaintext credentials from web browsers. For example, on Windows systems, encrypted credentials may be obtained from Google Chrome by reading a database file, <code>AppData\Local\Google\Chrome\User Data\Default\Login Data</code> and executing a SQL query: <code>SELECT action_url, username_value, password_value FROM logins;</code>. The plaintext password can then be obtained by passing the encrypted credentials to the Windows API function <code>CryptUnprotectData</code>, which uses the victim’s cached logon credentials as the decryption key. Adversaries have executed similar procedures for common web browsers such as FireFox, Safari, Edge, etc. Windows stores Internet Explorer and Microsoft Edge credentials in Credential Lockers managed by the Windows Credential Manager. Adversaries may also acquire credentials by searching web browser process memory for patterns that commonly match credentials. After acquiring credentials from web browsers, adversaries may attempt to recycle the credentials across different systems and/or accounts in order to expand access. This can result in significantly furthering an adversary's objective in cases where credentials gained from web browsers overlap with privileged accounts (e.g. domain administrator).

Platforms: Linux, macOS, WindowsParent: T1555 Credentials from Password StoresMITRE ATT&CK ↗

Used by actors

23 known groups

Software

64 malware/tools implement this

MimikatzPinchDukeCosmicDukeBlackEnergyBackdoor.OldreaTrojan.KaraganyPrikormkaCrimsonUnknown LoggerH1N1OLDBAITChChesRedLeavesXAgentOSXPupyNETWIRESmoke LoaderROKRATZebrocyQuasarRATTrickBotProtonjRATAgent TeslaAzorultLaZagneKONNIEmpireOlympic DestroyerEmotetnjRATKeyBoyMachetePoetRATImminent MonitorPLEADTSCookieLokibotCarberpCookieMinerKGH_SPYJavaliMelcozGrandoreiroRainyDayChaesQakBotBLUELIGHTWarzoneRATLizarSILENTTRINITYSUGARDUMPMispaduMgBotRaccoon StealerManjusakaTRANSLATEXTXLoaderLumma StealerRedLine StealerInvisibleFerretBeaverTailGlassWormMirrorStealer

Corpus indicators tagged with this technique

5,634 indicators in the corpus carry T1555.003.

IndicatorTypeFamilySevSrc
cve-2025-1055cveransomware853
cve-2023-52271cveransomware853
cve-2025-61155cveransomware853
512adab2c69feaf026adfb12cbd7d2eb4fee746120491e44f476eebddcbb19f2sha256801
6328567511d88fdc2ae0939c5ef17b7a63d2a833881900de018a4f12f4982525sha256prompt_injection802
ccca11a6d5835999c40a0a5264084b3740633600c157754fad2ef59559e31736sha256801
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
2af0a6135df3502a7f6de4d2de6db73bhash803
65c053030558b4a3588e2590c5c4961a9912180b731686deb3f4c831e765a095hash803
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
c8075bbff748096e1c6a1ea0aa67bb6762fdd7551427a12425b35b94c1f1ecf2sha256supply_chain801
50ffce607867d8fa8eaf6ef5cd25a3c0e7e4415e881b9e55c04a67bcddb74fdfsha256supply_chain801
6c6cbed6aad96564ed87094785be07a1hashphishing802
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
22b07d2af98bb180474c33d93861124bbdf9b5dd7e42a8bddc654310469a9a2chash803
24398b75be2645e6c695e529e62e60deb418143a4bbea13c561d3c361419eb54hash802
606966a9ec33765baedf63331595d1168f2a596fhash803
1c170b7470d507378ddb78e9d66305f1184e965baaf2d27ededb23a318a58953hash804
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
f6669bd504ce6b0e303be7ee47f2ebbc062989c88c41f0a3f436044a24869798sha256supply_chain801
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81hashphishing802
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10hashphishing802
17832aa629524ef6e8d8d6e9b6b902a8d324b559e3c36dbd0e221ab1690be871sha256supply_chain801
164e322d6fbc62e254d73583acd7f39444c884d3f5e6a5d27db143fc25bc88b3sha256supply_chain801
282b9bc318ad1234cbd1b86424b784299b8be31545802a7c6b751166b814b990sha256supply_chain801
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801

Showing the top 30 by severity of 5,634.