# T1555.003 Credentials from Web Browsers

> As of 2026-10-05, T1555.003 (Credentials from Web Browsers) appears in 262 tracked threats, first reported 2026-01-14 and most recently 2026-10-04, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 262 (29 critical, 208 high, 24 medium, 1 low)
- **First seen:** 2026-01-14
- **Last seen:** 2026-10-04
- **Threat actors:** 80
- **Detection rules:** 521 (counts only; Blue tier and above)

## Key facts

- **ID:** T1555.003
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Parent:** T1555
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1555/003/

## Activity timeline

T1555.003 first appeared in tracked threats on 2026-01-14 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 76 reports, and 262 of the 262 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1555.003 Credentials from Web Browsers is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix, as a sub-technique of [T1555 Credentials from Password Stores](https://intel.threadlinqs.com/technique/T1555). Threadlinqs maps 262 of 2623 tracked threats (10%) to it; by severity that is 29 critical, 208 high, 24 medium, 1 low.

Threats that use T1555.003 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (200 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (178 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (171 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (163 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (156 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

80 tracked threat actors appear in the threats that use T1555.003; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (15), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (9), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (9), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (7), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (6).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1555.003.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)

## Data sources

Telemetry that can reveal T1555.003, per MITRE ATT&CK.

- Command — Command Execution
- File — File Access
- Process — OS API Execution, Process Access

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 15
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 9
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 9
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 7
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 5
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 5
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 5
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 5
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 4
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 4

## Tracked threats

The 30 most recent of 262 tracked threats that use T1555.003.

- [Snowflake customer-account extortion campaign (UNC5537): Canadian suspect Connor Riley Moucka pleads guilty](https://intel.threadlinqs.com/threat/TL-2026-2908) — high — 2026-10-04
- [Attackers Abuse Microsoft SQL Server xp_cmdshell as Command and Base64 Data-Exfiltration Channel in Viva…](https://intel.threadlinqs.com/threat/TL-2026-2868) — high — 2026-10-03
- [ClickFix Campaign Uses Fake CAPTCHA Lures and Browser-Cache Staging to Execute Malicious Commands on Windows…](https://intel.threadlinqs.com/threat/TL-2026-2858) — high — 2026-10-03
- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — high — 2026-10-02
- [DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2](https://intel.threadlinqs.com/threat/TL-2026-2836) — high — 2026-10-01
- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — high — 2026-09-30
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)](https://intel.threadlinqs.com/threat/TL-2026-2757) — high — 2026-09-28
- [Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)](https://intel.threadlinqs.com/threat/TL-2026-2752) — high — 2026-09-28
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer](https://intel.threadlinqs.com/threat/TL-2026-2699) — high — 2026-09-27
- [Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)](https://intel.threadlinqs.com/threat/TL-2026-2698) — high — 2026-09-27
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited](https://intel.threadlinqs.com/threat/TL-2026-2667) — high — 2026-09-26
- [Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2664) — high — 2026-09-26
- [Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)](https://intel.threadlinqs.com/threat/TL-2026-2713) — medium — 2026-09-25
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Macfinger ClickFix Campaign Delivers Atomic macOS Stealer (AMOS) via Fake Verification Prompts](https://intel.threadlinqs.com/threat/TL-2026-2622) — high — 2026-09-23
- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [eBPF Rootkit Detection: VoidLink, LinkPro, and Atomic Arch Evade Kernel-Level Monitoring](https://intel.threadlinqs.com/threat/TL-2026-2624) — medium — 2026-09-22
- [ClosedQuorum: Go-Based Windows Implant Delegates Post-Compromise Decisions to a Four-Model LLM Voting Panel](https://intel.threadlinqs.com/threat/TL-2026-2621) — medium — 2026-09-22
- [Cisco Talos Open-Sources CAIRN to Hunt AI-Integrated Malware; Discloses CLOSEDQUORUM, First Documented…](https://intel.threadlinqs.com/threat/TL-2026-2615) — medium — 2026-09-22
- [GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcp](https://intel.threadlinqs.com/threat/TL-2026-2605) — high — 2026-09-21
- [Trusted AI Platforms Weaponized as Malware Distribution Channels: Claude Artifacts, ChatGPT, and Grok Abused…](https://intel.threadlinqs.com/threat/TL-2026-2604) — high — 2026-09-21
- [Rust Team Members and Popular Crate Owners Targeted via Fake Job Video Calls (North Korea-Linked)](https://intel.threadlinqs.com/threat/TL-2026-2603) — high — 2026-09-21

## Related CVEs

CVEs referenced by the tracked threats that use T1555.003, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2022-42045](https://intel.threadlinqs.com/cve/CVE-2022-42045)
- [CVE-2023-52271](https://intel.threadlinqs.com/cve/CVE-2023-52271)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-1055](https://intel.threadlinqs.com/cve/CVE-2025-1055)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-20598](https://intel.threadlinqs.com/cve/CVE-2023-20598)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-7028](https://intel.threadlinqs.com/cve/CVE-2023-7028)
- [CVE-2024-23897](https://intel.threadlinqs.com/cve/CVE-2024-23897)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2024-6387](https://intel.threadlinqs.com/cve/CVE-2024-6387)
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333)
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362)

## Detection coverage

Threadlinqs maintains 521 detection rules mapped to T1555.003 (SPL 152, KQL 228, Sigma 140, other 1). Rule content is available to Blue tier accounts and above; this page shows counts only.

521 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1555 Credentials from Password Stores](https://intel.threadlinqs.com/technique/T1555) — 445 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1555.003
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
