T1003 OS Credential Dumping in real malware
ATT&CK technique T1003 OS Credential Dumping appears in 317 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.3% of the analyzed corpus. Seven-day prevalence is falling (0 recent vs 3 prior). Most associated families: Beebone, HUILoader, RedLine.
Tactics: credential-access
Prevalence in the corpus
- Samples exhibiting T1003: 317
- Share of analyzed corpus: 0.3%
- Last 7 days: 0 · prior 7 days: 3 (falling)
Malware families using T1003
Example samples
- pp.exe - suspicious
- mimikaz.exe - malicious
- CUIDADO_bmtv-lock_encryptador_etc_DANGER_danger.zip - malicious
- 10fe5a61eef054cc9eaf91e3f7e9c682f00f81871381ef5ce19085e0ccfac1a6 - malicious
- cef9a5ad66b8e798a1ddb77a7791b9c9cc0f619928eefe3fc7ffe333f34e9775 - malicious
- 59eb0ae37ec08651665874bcd99326b9d7f3a00e550948e7b8c3ed9142d4ec9c - malicious
- bae6157ecc8725f45770344bd174e6eef095660d3b89e042130bb154909e95ad - malicious
- af294107e6474acf33a9f09347dc25a89df8ebc9c73e7835ba13ae05bba14475 - malicious
- 58e4c7b1cf10849700e4112f1c34da25addd8030ebe6d8a8e95fcbf4ea28a897 - malicious
- 302f2ad9107d8f57118f70343c8fd46d663cd5fefea838820f423c5f8aa6d4ea - malicious
- d8552bd62f73b1da3e620b30e6b7cca695af48474d721e8cb9b5a373113b0ad1 - malicious
- 27eea605084be3053b574811d2b879a1296fd5ad9b9f579124664ca2160b95dd - malicious
- 3e5ac7b07aad0ac1cf03f34de22eeca807515612d9a5368b3770401626017cda - malicious
- ffafe2b75352673dbae846022f94d08b5f94e099b86f9041a7428b71f94303f5 - malicious
- 4b52969f3d51129d1355e03619226e16c2436a2de0bc232614bedc2934e07231 - malicious
- 4f3906fb12551ffa9db7e9d9abac33d3cde8f46062854dafd5439d6522e0a771 - malicious
- 03216d525ba58e647dfbb00c0ae8528af967047a3783d57975d77682cdfafab6 - malicious
- fac8504e0f4e3324b1d48f875ed0822756a2d375c37ac1ab62d23889e8eac352 - malicious
- 66ccb36c0ad269026447fb2f5f4b5c6ffdb3caca5de553c7ae4cdbffee4ed81d - malicious
- 289805a8bcf2d236b137984ed925ad161b2e7f19234974f658b94a103037e2fe - malicious
- 6bbcba7c45ed953f0937b739281638c1199034da36dfb31fb3280e6de3571e4b - malicious
- virussign.com_1e8faa0ee2cdd8e7c1ffc04a13b46760.vir - malicious
- virussign.com_eb8208a284f2b7dbbd1fc66568e8f6d0.vir - malicious
- virussign.com_fc5da94e002665e2962d923de71483c0.vir - malicious
- virussign.com_5933fbd0b6ab381dd1bfab0dfbe4df00.vir - malicious
Canonical technique definition: MITRE ATT&CK T1003 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1003
- How common is ATT&CK T1003 (OS Credential Dumping) in real malware?
- ATT&CK technique T1003 OS Credential Dumping appears in 317 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.3% of the analyzed corpus. Seven-day prevalence is falling (0 recent vs 3 prior). Most associated families: Beebone, HUILoader, RedLine.
- Is T1003 becoming more common?
- Prevalence is falling: 0 samples in the last seven days against 3 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1003?
- In this corpus T1003 is most associated with Beebone (96), HUILoader (26), RedLine (8). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1003?
- 0.3% of the publicly analyzed corpus (317 of 114611 samples) exhibits T1003. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats