XenAllPasswordPro is a credential-harvesting utility used in post-compromise operations to extract authentication data from local password stores. It has been observed recovering saved credentials from Mozilla Firefox and Thunderbird through use of Mozilla NSS libraries, as well as harvesting credentials from other system and browser stores. The tool has been deployed remotely over SMB and executed through WMI or Remote Desktop Protocol following intrusion. It has been used by ransomware and extortion actors including Crypt Ghouls and The Gentlemen, as well as the hacktivist group Cyber Anarchy Squad, in operations involving credential access, lateral movement, and ransomware deployment. Crypt Ghouls activity placed the tool in a recurring allinone2023 directory structure and targeted Russian government agencies and organizations in the mining, energy, finance, and retail sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.
The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.
The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.
The attackers employed the XenAllPasswordPro tool to harvest a range of authentication data from the target system.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential harvesting tool used to collect authentication data from victim systems, commonly staged in directories named allinone2023 across multiple related campaigns.
A credential-harvesting utility used for browser and Mozilla-application credential extraction, deployed remotely through SMB and NetExec.
A credential-collection payload deployed broadly over SMB, with associated DLL dependencies staged on victim hosts.
XenAllPasswordPro is a credential stealer used by C.A.S to extract passwords from system storage on compromised hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.