Activity timeline
T1555.003 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 76 reports, and 262 of the 262 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1555.003 Credentials from Web Browsers is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of T1555 Credentials from Password Stores. Threadlinqs maps 262 of 2623 tracked threats (10%) to it; by severity that is 29 critical, 208 high, 24 medium, 1 low.
Threats that use T1555.003 most often also use T1071.001 Web Protocols (200 threats), T1005 Data from Local System (178 threats), T1027 Obfuscated Files or Information (171 threats), T1082 System Information Discovery (163 threats), T1204.002 Malicious File (156 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
80 tracked threat actors appear in the threats that use T1555.003; the most frequent are APT38 (15), Sapphire Sleet (9), Stardust Chollima (9), Contagious Interview (7), Andariel (6).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1555.003.
Data sources
Telemetry that can reveal T1555.003, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Process — OS API Execution, Process Access
Threat actors using it
Tracked threats
The 30 most recent of 262 tracked threats that use T1555.003.
- Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guiltyhigh
- Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…high
- ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…high
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)high
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)high
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealerhigh
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)high
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limitedhigh
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…high
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)medium
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogshigh
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Promptshigh
- CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)medium
- eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoringmedium
- ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panelmedium
- Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…medium
- GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcphigh
- Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…high
- Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)high
Detection coverage
Threadlinqs maintains 521 detection rules mapped to T1555.003 (SPL 152, KQL 228, Sigma 140, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1555 Credentials from Password Stores — 445 tracked threats at the technique level.