FireMalv is a custom-developed credential-stealing malware associated with the Iranian threat actor Ajax Security Team, also tracked as Magic Hound. Its documented function is harvesting passwords stored in Mozilla Firefox browser storage, indicating a focused browser credential theft capability intended to obtain account access from compromised systems. The malware has been used in intrusion activity attributed to this actor set and aligns with broader credential-access tradecraft aimed at collecting saved browser secrets for follow-on espionage or account compromise. High-confidence reporting supports Firefox as the specifically targeted platform and password theft from browser storage as the core behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage.
Magic Hound used FireMalv, custom-developed malware, which collected passwords from the Firefox browser storage.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom-developed malware used to collect passwords from Firefox browser storage.
Custom-developed malware used to collect passwords from Firefox browser storage.
Custom-developed malware used to collect passwords from Firefox browser storage.
Custom credential-stealing malware used to collect passwords from Firefox browser storage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.