typeconceptconfidencemediumcreated2026-06-28updated2026-06-28credential-accessdiscoverycollectionemail-theftinfostealer

Email Client Credential Theft

Overview

Cross-family technique: malware extracts saved credentials, account settings, and mail stores from local email client applications. Targets vary by family but commonly include Outlook, Thunderbird, FoxMail, Opera Mail, Mailbird, The Bat!, and Eudora.

Typical Targets

Client Credential Store
Outlook HKEY_CURRENT_USER\Software\Microsoft\Office\<version>\Outlook\Profiles
Thunderbird profiles.ini + logins.json / key4.db
FoxMail HKEY_CURRENT_USER\Software\Aerofox\Foxmail registry + mail directory
Opera Mail wand.dat
Mailbird Store.db
The Bat! registry + .tbk stores
Eudora CommandLine registry

Observed In

  • agenttesla — harvests Outlook (Office 11–16), Thunderbird, FoxMail, Opera Mail, Mailbird, The Bat!, Eudora ^[/intel/analyses/accd2ccd2be48b4303154bb87f87d0d6897441c18ca7b16b22fbaa8b68bbacbb.html]

Related