Meta tags:
Headings (most frequently used words):
credentials, from, password, stores, procedure, examples, mitigations, detection, strategy, references, sub, techniques,
Text of the page (most frequently used words):
and (60), retrieved (59), the (53), #credentials (38), from (32), password (23), for (16), passwords (16), has (16), 2018 (15), credential (15), may (14), july (14), 2020 (14), access (14), 2019 (14), t1555 (14), 2026 (13), march (13), 2024 (13), can (13), clients (13), cyber (12), security (11), december (11), att (10), all (10), april (10), 2021 (10), november (10), with (10), stored (10), new (9), 2025 (9), january (9), september (9), malware (9), august (9), stores (9), used (9), email (9), 2015 (8), enterprise (8), software (8), 2017 (8), group (8), threat (8), stealer (8), february (8), lazagne (8), information (8), including (8), 2023 (7), team (7), tools (7), ftp (7), data (6), techniques (6), cloud (6), october (6), 2016 (6), middle (6), steal (6), secrets (6), services (6), such (6), windows (6), outlook (6), obtained (6), mail (6), are (5), ics (5), mobile (5), none (5), 2022 (5), targets (5), june (5), east (5), targeted (5), keys (5), stealing (5), multiple (5), keychain (5), account (5), user (5), login (5), obtain (5), applications (5), mitre (4), campaigns (4), detection (4), campaign (4), redline (4), analysis (4), apt (4), espionage (4), centre (4), mimikatz (4), manager (4), monitors (4), process (4), databases (4), accounts (4), they (4), web (4), system (4), pinchduke (4), dumping (4), version (4), use (3), resources (3), cti (3), mitigations (3), defenses (3), sub (3), tactics (3), actor (3), teampcp (3), compromised (3), into (3), quasarrat (3), operation (3), plead (3), network (3), attack (3), netwire (3), muddywater (3), organizations (3), adversary (3), attacks (3), mispadu (3), many (3), national (3), report (3), dpapi (3), via (3), updates (3), manjusaka (3), malteiro (3), lokibot (3), leafminer (3), fin6 (3), evilnum (3), darkgate (3), carberp (3), astaroth (3), apt41 (3), detects (3), attempts (3), storage (3), vault (3), suspicious (3), known (3), store (3), browser (3), that (3), file (3), description (3), name (3), collect (3), solana (3), sources (3), instant (3), collects (3), victim (3), ability (3), associated (3), several (3), messaging (3), nirsoft (3), about (3), gather (3), corporation (2), policy (2), domains (2), reference (2), groups (2), components (2), analytics (2), strategies (2), assets (2), matrices (2), core (2), objects (2), formbook (2), google (2), significant (2), aqua (2), update (2), investigation (2), continued (2), research (2), deep (2), stage (2), detections (2), cherepanov (2), lyceum (2), center (2), stolen (2), apt34 (2), join (2), mandiant (2), evasive (2), earth (2), target (2), symantec (2), government (2), telecoms (2), trojan (2), using (2), trend (2), micro (2), correlation (2), targeting (2), cobalt (2), strike (2), zealand (2), ncsc (2), cert (2), publicly (2), available (2), retrieving (2), deply (2), module (2), popular (2), chinese (2), labs (2), clearsky (2), response (2), more (2), service (2), uses (2), processes (2), saudi (2), arabia (2), steals (2), wifi (2), api (2), calls (2), database (2), utilities (2), execution (2), files (2), anomalous (2), attempt (2), lsass (2), analytic (2), perform (2), risk (2), query (2), only (2), management (2), browsers (2), locations (2), additional (2), xloader (2), volt (2), typhoon (2), keystores (2), stealth (2), falcon (2), during (2), solarwinds (2), compromise (2), vpn (2), common (2), pupy (2), prikormka (2), decrypt (2), poshc2 (2), saved (2), microsoft (2), functionality (2), also (2), oldbait (2), oilrig (2), client (2), other (2), mailpassview (2), mirrorstealer (2), mgbot (2), matryoshka (2), various (2), platforms (2), kgh_spy (2), hexane (2), netpass (2), well (2), cosmicduke (2), details (2), macos (2), within (2), linux (2), beavertail (2), apt39 (2), apt33 (2), agent (2), tesla (2), adversaries (2), users (2), poland (2), wiper (2), 006 (2), 005 (2), 004 (2), 003 (2), 002 (2), 001 (2), search (2), managers (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, gustavo, palazolo, netskope, delivered, through, phishing, emails, nart, villeneuve, randi, eitzman, sandor, nemes, tyler, dean, distribution, impacting, south, korea, nsa, people, republic, china, state, sponsored, living, off, land, evade, fbi, criminal, ongoing, remediation, trivy, ecosystem, supply, chain, temporarily, marczak, scott, railton, keep, calm, don, enable, macros, uae, dissidents, mstic, cdoc, 365, defender, dive, solorigate, second, activation, sunburst, teardrop, raindrop, splunk, not, cross, proofpoint, insight, jeremy, axel, george, glass, redlinestealer, driving, initial, broker, market, meltzer, patchwork, think, tanks, maxxor, nicolas, verdier, groundbait, surveillance, toolkit, secureworks, takes, certificates, taiwanese, tech, companies, misused, fireeye, apt28, window, russia, operations, bromiley, hard, pass, declining, invite, their, professional, trends, davis, caban, unit42, serpens, unit, playbook, viewer, lambert, intro, peretz, theck, vetala, continues, deepsight, intelligence, seedworm, compromises, agencies, oil, gas, ngos, firms, lancaster, muddying, water, eset, advertisement, discounted, unhappy, meal, pedro, tavares, segurança, informática, emergent, ursa, impacts, countries, sophisticated, loader, spot, difference, kasha, lodeinfo, apt10, umbrella, breitenbacher, unmasking, mirrorface, liberalface, japanese, political, entities, strategic, llc, advanced, penetration, testers, australian, acsc, canadian, cccs, cybersecurity, communications, integration, nccic, joint, hacking, grafnetter, backup, active, directory, toux, lsadump, hunter, daggerfly, company, africa, facundo, muñoz, panda, delivers, minerva, ltd, copykittens, wilted, tulip, exposing, apparatus, asheer, malhotra, vitor, ventura, sibling, sliver, scilabs, profile, hoang, malicious, activity, elements, infostealer, eastern, regions, zanni, project, dahan, back, future, inside, kimsuky, kgh, spyware, suite, kayal, reborn, counterintelligence, visa, public, cybercrime, expands, ecommerce, merchants, porolli, evil, look, its, toolset, ernesto, fernández, provecho, pham, duy, phuc, ciana, driscoll, vinoo, thomas, evolution, giuliani, allievi, 2011, modular, matej, havranek, deceptivedevelopment, freelance, developers, salem, legitimate, antivirus, personal, nikita, rostovcev, world, tour, tight, schedule, rusu, iranian, chafer, air, transportation, kuwait, ackerman, overruled, containing, potentially, destructive, elfin, relentless, jazi, agenttesla, variant, polska, energy, sector, incident, secure, dukes, years, russian, cyberespionage, references, enumerate, aws, azure, key, gcp, secret, abnormal, enumeration, bulk, retrieval, an1201, invocations, osascript, correlates, dump, unlock, an1200, etc, shadow, gnome, keyring, kwallet, read, extract, an1199, accessing, reads, non, standard, an1198, detect, det0430, strategy, regular, mitigate, exploitation, m1051, limit, number, permission, those, required, ensure, permissions, have, require, privileged, m1026, consider, weighing, storing, disclosure, concern, technical, controls, training, prevent, improper, changed, this, increases, complexity, because, need, know, policies, m1027, mitigation, s1207, attempted, openssh, realvnc, putty, g1017, harvest, cryptocurrency, wallets, ethereum, cardano, validator, keypairs, ledger, device, anchor, deploy, s9041, gathers, g0038, managed, gmsa, apt29, c0024, messenger, chat, s1240, s0262, harvesting, s0192, installed, s0113, rdcman, configuration, s0378, s0435, hosts, believed, based, source, code, pinch, ldpinch, include, ones, bat, yahoo, passport, net, talk, s0048, s0138, logged, g0049, retrieve, s0198, performed, g0069, s1122, s9022, performs, useful, gaining, systems, contains, acquire, ways, s0002, includes, modules, foxmail, s1146, capable, s0167, extracts, registry, premiumsoft, navicat, utility, facilitate, types, s1156, g1026, sftp, s0447, g0077, across, s0349, winscp, s0526, run, machines, identify, cmdkey, g1001, one, transfer, g0037, victims, g0120, recovery, rdp, some, versions, s1111, programs, wlan, s0050, passw, plug, plugin, social, media, vnc, s0484, collected, local, share, keyrings, library, keychains, config, json, s1246, external, recover, s0373, lists, employees, plaintext, hashed, g0096, smartftp, decryptor, tool, g0087, variety, like, g0064, wireless, profiles, s0331, configured, native, cli, elevated, grep, c0063, procedure, examples, live, permalink, last, modified, created, iaas, tactic, places, depending, operating, application, holding, there, specific, make, them, easier, manage, maintain, vaults, once, lateral, movement, restricted, securityd, memory, home, open, mclean, hotel, location, found, register, here, blog, contribute, benefactors, legal, branding, history, engage, advisory, council, learn, get, started, technique,
Text of the page (random words):
rn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise credentials from password stores credentials from password stores sub techniques 6 id name t1555 001 keychain t1555 002 securityd memory t1555 003 credentials from web browsers t1555 004 windows credential manager t1555 005 password managers t1555 006 cloud secrets management stores adversaries may search for common password storage locations to obtain user credentials 1 passwords are stored in several places on a system depending on the operating system or application holding the credentials there are also specific applications and services that store passwords to make them easier for users to manage and maintain such as password managers and cloud secrets vaults once credentials are obtained they can be used to perform lateral movement and access restricted information id t1555 sub techniques t1555 001 t1555 002 t1555 003 t1555 004 t1555 005 t1555 006 ⓘ tactic credential access ⓘ platforms iaas linux windows macos version 1 2 created 11 february 2020 last modified 12 may 2026 version permalink live version procedure examples id name description c0063 2025 poland wiper attacks during the 2025 poland wiper attacks the adversaries configured a native cli to gather a targeted elevated users password using grep 2 s0331 agent tesla agent tesla has the ability to steal credentials from ftp clients and wireless profiles 3 g0064 apt33 apt33 has used a variety of publicly available tools like lazagne to gather credentials 4 5 g0087 apt39 apt39 has used the smartftp password decryptor tool to decrypt ftp passwords 6 g0096 apt41 apt41 has obtained information about accounts lists of employees and plaintext and hashed passwords from databases 7 s0373 astaroth astaroth uses an external software known as netpass to recover passwords 8 s1246 beavertail beavertail has collected keys stored for solana stored in config solana id json and other login details associated with macos within library keychains login keychain or for linux within local share keyrings 9 s0484 carberp carberp s passw plug plugin can gather account information from multiple instant messaging email and social media services as well as ftp vnc and vpn clients 10 s0050 cosmicduke cosmicduke collects user credentials including passwords for various programs including popular instant messaging applications and email clients as well as wlan keys 1 s1111 darkgate darkgate use nirsoft network password recovery or netpass tools to steal stored rdp credentials in some malware versions 11 g0120 evilnum evilnum can collect email credentials from victims 12 g0037 fin6 fin6 has used the stealer one credential stealer to target e mail and file transfer utilities including ftp 13 g1001 hexane hexane has run cmdkey on victim machines to identify stored credentials 14 s0526 kgh_spy kgh_spy can collect credentials from winscp 15 s0349 lazagne lazagne can obtain credentials from databases mail and wifi across multiple platforms 16 g0077 leafminer leafminer used several tools for retrieving login and password information including lazagne 17 s0447 lokibot lokibot has stolen credentials from multiple applications and data sources including windows os credentials email clients ftp and sftp clients 18 g1026 malteiro malteiro has obtained credentials from mail clients via nirsoft mailpassview 19 s1156 manjusaka manjusaka extracts credentials from the windows registry associated with premiumsoft navicat a utility used to facilitate access to various database types 20 s0167 matryoshka matryoshka is capable of stealing outlook passwords 21 22 s1146 mgbot mgbot includes modules for stealing stored credentials from outlook and foxmail email client software 23 24 s0002 mimikatz mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources it contains functionality to acquire information about credentials in many ways including from the credential vault and dpapi 25 26 27 28 29 s9022 mirrorstealer mirrorstealer has the ability to steal credentials from email clients 30 31 s1122 mispadu mispadu has obtained credentials from mail clients via nirsoft mailpassview 19 32 33 g0069 muddywater muddywater has performed credential dumping with lazagne and other tools including by dumping passwords saved in victim email 34 35 36 s0198 netwire netwire can retrieve passwords from messaging and mail client applications 37 g0049 oilrig oilrig has used credential dumping tools such as lazagne to steal credentials to accounts logged into the compromised system and to outlook web access 38 39 40 41 s0138 oldbait oldbait collects credentials from several email clients 42 s0048 pinchduke pinchduke steals credentials from compromised hosts pinchduke s credential stealing functionality is believed to be based on the source code of the pinch credential stealing malware also known as ldpinch credentials targeted by pinchduke include ones associated with many sources such as the bat yahoo mail ru passport net google talk and microsoft outlook 1 s0435 plead plead has the ability to steal saved passwords from microsoft outlook 43 s0378 poshc2 poshc2 can decrypt passwords stored in the rdcman configuration file 44 s0113 prikormka a module in prikormka collects passwords stored in applications installed on the victim 45 s0192 pupy pupy can use lazagne for harvesting credentials 46 s0262 quasarrat quasarrat can obtain passwords from common ftp clients 47 48 s1240 redline stealer redline stealer has obtained credentials from vpn services ftp clients and instant messenger im chat clients 49 50 51 c0024 solarwinds compromise during the solarwinds compromise apt29 used account credentials they obtained to attempt access to group managed service account gmsa passwords 52 g0038 stealth falcon stealth falcon malware gathers passwords from multiple sources including windows credential vault and outlook 53 s9041 teampcp cloud stealer teampcp cloud stealer can harvest credentials from cryptocurrency wallets and keystores such as ethereum keystores cardano keys solana validator keypairs ledger device files and anchor deploy keys 54 55 56 g1017 volt typhoon volt typhoon has attempted to obtain credentials from openssh realvnc and putty 57 s1207 xloader xloader can collect credentials stored in email clients 58 59 mitigations id mitigation description m1027 password policies the password for the user s login keychain can be changed from the user s login password this increases the complexity for an adversary because they need to know an additional password organizations may consider weighing the risk of storing credentials in password stores and web browsers if system software or web browser credential disclosure is a significant concern technical controls policy and user training may be used to prevent storage of credentials in improper locations m1026 privileged account management limit the number of accounts and services with permission to query information from password stores to only those required ensure that accounts and services with permissions to query password stores only have access to the secrets they require m1051 update software perform regular software updates to mitigate exploitation risk detection strategy id name analytic id analytic description det0430 detect credentials access from password stores an1198 monitors suspicious access to password stores such as lsass dpapi windows credential manager or browser credential databases detects anomalous process to process access e g mimikatz accessing lsass and correlation of credential store file reads with execution of non standard processes an1199 detects access to known password store files e g etc shadow gnome keyring kwallet browser credential databases monitors anomalous process read attempts and suspicious api calls that attempt to extract stored credentials an1200 monitors keychain database access and suspicious invocations of security and osascript utilities correlates process execution with attempts to dump or unlock keychain data an1201 detects attempts to access or enumerate cloud password secrets storage services such as aws secrets manager azure key vault or gcp secret manager monitors api calls for abnormal enumeration or bulk retrieval of secrets references f secure labs 2015 september 17 the dukes 7 years of russian cyberespionage retrieved december 10 2015 cert polska 2026 january 30 energy sector incident report 29 december retrieved april 22 2026 jazi h 2020 april 16 new agenttesla variant steals wifi credentials retrieved may 19 2020 security response attack investigation team 2019 march 27 elfin relentless espionage group targets multiple organizations in saudi arabia and u s retrieved april 10 2019 ackerman g et al 2018 december 21 overruled containing a potentially destructive adversary retrieved january 17 2019 rusu b 2020 may 21 iranian chafer apt targeted air transportation and government in kuwait and saudi arabia retrieved may 22 2020 nikita rostovcev 2022 august 18 apt41 world tour 2021 on a tight schedule retrieved february 22 2024 salem e 2019 february 13 astaroth malware uses legitimate os and antivirus processes to steal passwords and personal data retrieved april 17 2019 matej havranek 2025 february 20 deceptivedevelopment targets freelance developers retrieved october 17 2025 giuliani m allievi a 2011 february 28 carberp a modular information stealing trojan retrieved september 12 2024 ernesto fernández provecho pham duy phuc ciana driscoll vinoo thomas 2023 november 21 the continued evolution of the darkgate malware as a service retrieved february 9 2024 porolli m 2020 july 9 more evil a deep look at evilnum and its toolset retrieved january 22 2021 visa public 2019 february fin6 cybercrime group expands threat to ecommerce merchants retrieved september 16 2019 kayal a et al 2021 october lyceum reborn counterintelligence in the middle east retrieved june 14 2022 dahan a et al 2020 november 2 back to the future inside the kimsuky kgh spyware suite retrieved november 6 2020 zanni a n d the lazagne project retrieved december 14 2018 symantec security response 2018 july 25 leafminer new espionage campaigns targeting middle eastern regions retrieved august 28 2018 hoang m 2019 january 31 malicious activity report elements of lokibot infostealer retrieved may 15 2020 scilabs 2021 december 23 cyber threat profile malteiro retrieved march 13 2024 asheer malhotra vitor ventura 2022 august 2 manjusaka a chinese sibling of sliver and cobalt strike retrieved september 4 2024 clearsky cyber security and trend micro 2017 july operation wilted tulip exposing a cyber espionage apparatus retrieved august 21 2017 minerva labs ltd and clearsky cyber security 2015 november 23 copykittens attack group retrieved november 17 2024 facundo muñoz 2023 april 26 evasive panda apt group delivers malware via updates for popular chinese software retrieved july 25 2024 threat hunter team 2023 april 20 daggerfly apt actor targets telecoms company in africa retrieved july 25 2024 deply b n d mimikatz retrieved september 29 2015 deply b le toux v 2016 june 5 module lsadump retrieved august 7 2017 grafnetter m 2015 october 26 retrieving dpapi backup keys from active directory retrieved december 19 2017 the australian cyber security centre acsc the canadian centre for cyber security cccs the new zealand national cyber security centre nz ncsc cert new zealand the uk national cyber security centre uk ncsc and the us national cybersecurity and communications integration center nccic 2018 october 11 joint report on publicly available hacking tools retrieved march 11 2019 strategic cyber llc 2020 november 5 cobalt strike advanced threat tactics for penetration testers retrieved april 13 2021 breitenbacher d 2022 december 14 unmasking mirrorface operation liberalface targeting japanese political entities retrieved april 17 2026 trend micro 2024 november 19 spot the difference earth kasha s new lodeinfo campaign and the correlation analysis with the apt10 umbrella retrieved april 17 2026 pedro tavares segurança informática 2020 september 15 threat analysis the emergent ursa trojan impacts many countries using a sophisticated loader retrieved march 13 2024 eset security 2019 november 19 mispadu advertisement for a discounted unhappy meal retrieved march 13 2024 lancaster t 2017 november 14 muddying the water targeted attacks in the middle east retrieved march 15 2018 symantec deepsight adversary intelligence team 2018 december 10 seedworm group compromises government agencies oil gas ngos telecoms and it firms retrieved december 14 2018 peretz a and theck e 2021 march 5 earth vetala muddywater continues to target organizations in the middle east retrieved march 18 2021 lambert t 2020 january 29 intro to netwire retrieved january 7 2021 unit42 2016 may 1 evasive serpens unit 42 playbook viewer retrieved february 6 2023 davis s and caban d 2017 december 19 apt34 new targeted attack in the middle east retrieved december 20 2017 mandiant 2018 mandiant m trends 2018 retrieved november 17 2024 bromiley m et al 2019 july 18 hard pass declining apt34 s invite to join their professional network retrieved august 26 2019 fireeye 2015 apt28 a window into russia s cyber espionage operations retrieved august 19 2015 cherepanov a 2018 july 9 certificates stolen from taiwanese tech companies misused in plead malware campaign retrieved may 6 2020 secureworks 2019 august 27 lyceum takes center stage in middle east campaign retrieved 2019 11 19 cherepanov a 2016 may 17 operation groundbait analysis of a surveillance toolkit retrieved may 18 2016 nicolas verdier n d retrieved january 29 2018 maxxor n d quasarrat retrieved july 10 2018 meltzer m et al 2018 june 07 patchwork apt group targets us think tanks retrieved july 16 2018 george glass 2024 august 14 redlinestealer malware driving the initial access broker market retrieved september 17 2025 proofpoint threat insight team jeremy h axel f 2020 march 16 new redline password stealer malware retrieved september 17 2025 splunk threat research team 2023 june 1 do not cross the redline stealer detections and analysis retrieved september 17 2025 mstic cdoc 365 defender research team 2021 january 20 deep dive into the solorigate second stage activation from sunburst to teardrop and raindrop retrieved january 22 2021 marczak b and scott railton j 2016 may 29 keep calm and don t enable macros a new threat actor targets uae dissidents retrieved june 8 2016 aqua security 2026 march 21 trivy ecosystem supply chain temporarily compromised retrieved july 1 2026 aqua team 2026 april 1 update ongoing inv...
|