WebBrowserPassView is a legitimate NirSoft password-recovery utility for Windows that extracts credentials saved by web browsers. Although it is freeware rather than malware in its original form, it is widely abused by threat actors as a credential-harvesting component during post-compromise operations. It has been observed used directly, packed, hidden inside multi-stage malware chains, and trojanized to write harvested credentials for later collection and exfiltration.
Its primary function is to recover usernames and passwords stored by browsers, including Internet Explorer, Microsoft Edge, Google Chrome, Mozilla Firefox, Opera, Safari, SeaMonkey, Yandex, Vivaldi, Waterfox, and other Chromium-based browsers. In malicious operations, the tool is commonly executed after initial access to dump browser-stored credentials, which can then support account takeover, privilege escalation, lateral movement, and broader compromise of enterprise environments.
WebBrowserPassView has appeared in campaigns and intrusions involving both cybercrime and state-linked actors. It has been used by malware families and intrusion sets including Emotet, Astaroth, Kimsuky, and activity clusters associated with APT41, as well as in ransomware intrusions involving ALPHV/BlackCat and Qilin affiliates. Observed delivery is typically indirect: the tool is downloaded or unpacked by another malware family, embedded as a plugin in fileless or living-off-the-land attack chains, or deployed manually by operators after foothold establishment. In some cases, trojanized variants have been injected into processes or modified to log recovered credentials to disk for later exfiltration.
Because it is a legitimate administrative-style utility, WebBrowserPassView is often used to blend malicious credential theft with otherwise ordinary system activity. Its abuse is especially common on Windows endpoints in espionage, ransomware, and financially motivated intrusions where browser-saved credentials provide rapid access to internal services, cloud accounts, email, and other sensitive resources.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WebBrowserPassView, a NirSoft tool that extracts stored web browser credentials to the file path specified with the /stext argument.
Credential Theft: WebBrowserPassView is downloaded, decrypted and executed to extract browser-related credentials. Those credentials, together with system information, are exfiltrated to the command-and-control (C2) server.
Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.
Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.
The actor uses Mimikatz to harvest the hashes from the lsass process address space and WebBrowserPassView to get all credentials stored in the web browsers.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Both executables are Base64 encoded and then obfuscated with a char-by-char XOR operation that uses the key "3."
They are extracted, injected into another executable and run once to steal the victim’s passwords, which are then exfiltrated to the C&C server.
Emotet executed a process that steals cookies or web and email credentials from client credential databases.
T1552.001 — Unsecured Credentials: Credentials In Files (Credential Access)
EMOTETは感染PC内に保存された様々な認証情報を窃取しますが、その際、フリーツールのNirSoftを悪用していることを確認しました。
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate password recovery tool abused by attackers to extract saved browser credentials from compromised systems.
NirSoft credential recovery utility used to extract saved web browser passwords for credential harvesting.
A credential-dumping utility used here to extract browser-stored credentials and exfiltrate them to a C2 server.
A password recovery and credential access tool used to extract stored browser credentials during attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.