WebBrowserPassView is a legitimate, closed-source freeware password-recovery utility developed by NirSoft for Windows. It extracts usernames and passwords saved by supported web browsers, including Internet Explorer, Microsoft Edge, Google Chrome, Mozilla Firefox, Opera, and other Chromium-based browsers. Recovered records can include associated website information, browser names, and credential metadata, and can be exported to a text file through command-line options. It is not inherently malware, but threat actors routinely abuse it for browser credential theft after compromising a system.
WebBrowserPassView has been incorporated into credential-harvesting components used by Emotet, Astaroth, and earlier Mispadu variants. Emotet has executed it through process-hollowing modules, while Astaroth has concealed it among encrypted components stored in NTFS alternate data streams. These surrounding malware components handle payload deployment and exfiltration of recovered credentials. Kimsuky has also used the utility, including a trojanized version modified to write harvested credentials to a log rather than display them interactively. ALPHV/BlackCat- and Qilin-associated attackers have deployed it during post-compromise credential harvesting. Its malicious use spans cybercrime and espionage operations; it does not have a single intrinsic infection vector or industry-specific target set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WebBrowserPassView, a NirSoft tool that extracts stored web browser credentials to the file path specified with the /stext argument.
Credential Theft: WebBrowserPassView is downloaded, decrypted and executed to extract browser-related credentials. Those credentials, together with system information, are exfiltrated to the command-and-control (C2) server.
Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.
Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.
The actor uses Mimikatz to harvest the hashes from the lsass process address space and WebBrowserPassView to get all credentials stored in the web browsers.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Both executables are Base64 encoded and then obfuscated with a char-by-char XOR operation that uses the key "3."
They are extracted, injected into another executable and run once to steal the victim’s passwords, which are then exfiltrated to the C&C server.
Emotet executed a process that steals cookies or web and email credentials from client credential databases.
T1552.001 — Unsecured Credentials: Credentials In Files (Credential Access)
EMOTETは感染PC内に保存された様々な認証情報を窃取しますが、その際、フリーツールのNirSoftを悪用していることを確認しました。
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate password recovery tool abused by attackers to extract saved browser credentials from compromised systems.
NirSoft credential recovery utility used to extract saved web browser passwords for credential harvesting.
A credential-dumping utility used here to extract browser-stored credentials and exfiltrate them to a C2 server.
A password recovery and credential access tool used to extract stored browser credentials during attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.