BrowserPasswordDump10 is a publicly available credential-dumping utility that extracts passwords saved in web browsers. The cyberespionage group Molerats has used it to harvest browser-stored passwords from compromised victims. Its documented role is credential theft, distinct from the remote-access capabilities provided by other tools in the group's arsenal.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
To dump passwords saved in victims' browsers, the group uses the publicly available BrowserPasswordDump10 tool.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential stealer used by Molerats to extract browser-stored passwords.
Publicly available tool used by Molerats to extract passwords stored in victims' browsers.
Public tool used to dump passwords saved in browsers.
Public tool used to dump passwords saved in victim browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.