typeconceptconfidencehighcreated2026-06-28updated2026-08-08credential-accessdiscoverycollectionbrowser-theftinfostealer

Browser Credential Harvesting

Overview

Cross-family technique: malware reads browser credential databases from local disk to extract saved passwords, cookies, and autofill data. Targets vary by family but commonly include Chromium-based browsers (Chrome, Edge, Brave, Opera) and Gecko-based browsers (Firefox, Thunderbird).

Typical Targets

Browser Credential File Path
Chrome / Edge / Brave Login Data (SQLite) %LOCALAPPDATA%\Google\Chrome\User Data\Default\
Firefox logins.json + key4.db %APPDATA%\Mozilla\Firefox\Profiles\<profile>\
Opera Login Data %APPDATA%\Opera Software\Opera Stable\
Old Firefox signons.sqlite Same profile directory

Decryption (Evolved)

  • Chromium-based browsers use DPAPI (CryptProtectData) to encrypt the master key; malware running as the same user can call CryptUnprotectData without elevation.
  • Firefox uses NSS/3DES or AES-256-CBC with a key derived from key4.db.
  • Chrome 127+ introduced App-Bound Encryption (ABE), which binds the master key to the browser process identity. Malware must now either inject into the browser process, use a Chrome extension with elevated privileges, or extract the app_bound_encrypted_key field and decrypt it with the correct service identity. Observed in unclassified-msvc-browser-credential-harvester with fallback to legacy DPAPI. See chrome-app-bound-encryption-bypass.

Observed In

  • agenttesla — harvests Chrome, Edge, Firefox, Opera, Brave, UC Browser, Torch, Flock, Falkon, QQ Browser, Mozilla icecat ^[/intel/analyses/accd2ccd2be48b4303154bb87f87d0d6897441c18ca7b16b22fbaa8b68bbacbb.html]
  • acrstealer — Go-based infostealer with custom DPAPI implementation
  • maskgramstealer — wallet-seed regex + browser credential theft via Telegram exfil
  • unclassified-msvc-browser-credential-harvester — MSVC 14.50 x64 DLL with Chrome App-Bound Encryption (ABE) bypass, SQLite 3.49.1 aggregation, and ASTER_KEY: debug prefix ^[/intel/analyses/9d3d5ac032a3d26671c21b3b8832c46785f30523b3631ff2d59d5eaf3494d661.html]

ATT&CK Mapping

  • T1003 — OS Credential Dumping
  • T1555.003 — Credentials from Web Browsers

Related