Browser Credential Harvesting
Overview
Cross-family technique: malware reads browser credential databases from local disk to extract saved passwords, cookies, and autofill data. Targets vary by family but commonly include Chromium-based browsers (Chrome, Edge, Brave, Opera) and Gecko-based browsers (Firefox, Thunderbird).
Typical Targets
| Browser | Credential File | Path |
|---|---|---|
| Chrome / Edge / Brave | Login Data (SQLite) |
%LOCALAPPDATA%\Google\Chrome\User Data\Default\ |
| Firefox | logins.json + key4.db |
%APPDATA%\Mozilla\Firefox\Profiles\<profile>\ |
| Opera | Login Data |
%APPDATA%\Opera Software\Opera Stable\ |
| Old Firefox | signons.sqlite |
Same profile directory |
Decryption (Evolved)
- Chromium-based browsers use DPAPI (
CryptProtectData) to encrypt the master key; malware running as the same user can callCryptUnprotectDatawithout elevation. - Firefox uses NSS/3DES or AES-256-CBC with a key derived from
key4.db. - Chrome 127+ introduced App-Bound Encryption (ABE), which binds the master key to the browser process identity. Malware must now either inject into the browser process, use a Chrome extension with elevated privileges, or extract the
app_bound_encrypted_keyfield and decrypt it with the correct service identity. Observed in unclassified-msvc-browser-credential-harvester with fallback to legacy DPAPI. See chrome-app-bound-encryption-bypass.
Observed In
- agenttesla — harvests Chrome, Edge, Firefox, Opera, Brave, UC Browser, Torch, Flock, Falkon, QQ Browser, Mozilla icecat ^[/intel/analyses/accd2ccd2be48b4303154bb87f87d0d6897441c18ca7b16b22fbaa8b68bbacbb.html]
- acrstealer — Go-based infostealer with custom DPAPI implementation
- maskgramstealer — wallet-seed regex + browser credential theft via Telegram exfil
- unclassified-msvc-browser-credential-harvester — MSVC 14.50 x64 DLL with Chrome App-Bound Encryption (ABE) bypass, SQLite 3.49.1 aggregation, and
ASTER_KEY:debug prefix ^[/intel/analyses/9d3d5ac032a3d26671c21b3b8832c46785f30523b3631ff2d59d5eaf3494d661.html]
ATT&CK Mapping
- T1003 — OS Credential Dumping
- T1555.003 — Credentials from Web Browsers
Related
- clipboard-hijack-cryptocurrency — complementary collection technique
- email-client-credential-theft — adjacent credential target
- chrome-app-bound-encryption-bypass — technique page for Chrome ABE bypass