T1555

Credentials from Password Stores

discovered 2026-06-17

Stage-2 reads Chrome/Brave/Edge profiles for 166 hardcoded crypto-wallet extension IDs (MetaMask, Phantom, Solflare, Coinbase Wallet, OKX, Keplr, TronLink, Binance Wallet, Argent X, Station, etc.).

View on MITRE ATT&CK

Seen in packages

Campaigns