TACTIC: CREDENTIAL ACCESS

Credentials from Password Stores (T1555): real cases

MITRE Definition ↗
Adversaries search local browser credential databases and keyrings for cached web passwords.

Key Facts

Technique ID
T1555
Credential Access
Mapped Cases
4
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1555.
  • Tactical Phase: Credential Access.
  • Substantiated in 4 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 24, Page 14
"Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers."
U.S. District Court for the Western District of Pennsylvania View full case dossier →
Primary Source Evidence Excerpt: DOJ Seizure Affidavit ¶ 12
"Genesis Market marketed specialized bots that packaged stolen browser cookies, session tokens, and passwords harvested by info-stealer malware."
U.S. District Court for the Eastern District of Wisconsin View full case dossier →
Primary Source Evidence Excerpt: Superseding Indictment ¶ 8, Page 4
"Kronos recorded user keystrokes and used form-grabbing browser hooks to intercept unencrypted login credentials from banking websites."
U.S. District Court for the Eastern District of Wisconsin View full case dossier →
Primary Source Evidence Excerpt: Plea Agreement ¶ 4, Page 5
"Defendant wrote Python scripts to parse massive unorganized text files exfiltrated by info-stealer trojans to isolate valid credit card numbers and passwords."
U.S. District Court for the Eastern District of Virginia View full case dossier →