BrowserPasswordDump10
BrowserPasswordDump10 is a publicly available credential-dumping tool used to extract passwords saved in web browsers on victim systems. The provided content specifically states that Molerats used BrowserPasswordDump10 to dump passwords saved in browsers on victims, and also lists it among tooling deployed by the group alongside BlackShades, DarkComet, SPARK RAT, and Quasar RAT. Based on the content, its known capability is browser-stored password theft; no additional high-confidence details about specific supported browsers, infection vector, persistence, or indicators of compromise are provided.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Molerats used the public tool BrowserPasswordDump10 to dump passwords saved in browsers on victims.
Techniques & procedures
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Credential Access
2 techniquesAPT3 has used tools to dump passwords from browsers... Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims... Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources.
To dump passwords saved in victims' browsers (T1555.003), the group uses the publicly available BrowserPasswordDump10 tool.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential stealer used by Molerats to extract browser-stored passwords.
Public tool used to dump passwords saved in browsers.
Public tool used to dump passwords saved in victim browsers.
Public tool used to dump passwords saved in victim web browsers.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.