T1555.001

Credentials from Password Stores: Keychain

discovered 2026-07-22

Reuses the phished login password to unlock the login Keychain and extract Safe Storage keys that decrypt Chromium-family cookies and saved passwords; also exfiltrates all *.keychain-db files.

View on MITRE ATT&CK

Seen in packages

Campaigns