TACTIC: CREDENTIAL ACCESS
Credentials from Password Stores (T1555): real cases
MITRE Definition ↗ Adversaries search local browser credential databases and keyrings for cached web passwords.
Key Facts
Technique ID
T1555
Credential Access
Mapped Cases
4
Primary sources
Related Laws
0
Criminal statutes
- ATT&CK Technique Identifier: T1555.
- Tactical Phase: Credential Access.
- Substantiated in 4 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)
fugitive 2019-11-14
Primary Source Evidence Excerpt: Indictment ¶ 24, Page 14
"Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
Operation Cookie Monster (Genesis Market Takedown)
alleged 2023-04-04
Primary Source Evidence Excerpt: DOJ Seizure Affidavit ¶ 12
"Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware."
U.S. District Court for the Eastern District of Wisconsin
View full case dossier →
U.S. v. Marcus Hutchins (Kronos Banking Malware)
sentenced 2017-07-12
Primary Source Evidence Excerpt: Superseding Indictment ¶ 8, Page 4
"Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites."
U.S. District Court for the Eastern District of Wisconsin
View full case dossier →
U.S. v. Aleksandr Brovko (Botnet Parsing & Credential Sales)
sentenced 2020-02-12
Primary Source Evidence Excerpt: Plea Agreement ¶ 4, Page 5
"Defendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords."
U.S. District Court for the Eastern District of Virginia
View full case dossier →