PICKPOCKET is a credential-stealing malware tool associated with the Iranian state-aligned threat group OilRig, also tracked as APT34 and Greenbug. It is designed to harvest credentials stored in web browsers and has been described as a browser credential-theft utility used in espionage operations. Reported functionality includes dumping saved website login credentials from major Windows browsers, specifically Chrome, Firefox, and Internet Explorer, and writing the recovered data to a file.
PICKPOCKET has been observed as part of OilRig’s broader malware arsenal alongside tools such as VALUEVAULT, LONGWATCH, OopsIE, Karkoff, ISMAgent, and Helminth. It appeared in a 2019 phishing campaign in which OilRig used social engineering and malicious documents to target organizations, particularly in Middle Eastern government, energy, utilities, and oil and gas sectors. In that activity, PICKPOCKET was identified alongside other credential-access and surveillance tooling, reinforcing its role in post-compromise collection of browser-stored secrets.
The malware’s primary purpose is credential access rather than remote administration or destructive action. Its use fits OilRig’s long-running cyber-espionage tradecraft, where stolen browser credentials can support account compromise, follow-on access, and broader intelligence collection within victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OilRig has also used tool named PICKPOCKET to dump passwords from web browsers.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Most recently in June 2019, a phishing campaign was observed asking victims to join their social network. This time the group masqueraded as a Cambridge University lecturer, also setting up a LinkedIn page in order to gain victims’ trust.
They use phishing emails to deliver weaponized Microsoft Excel documents... Between 2014 to 2016, the group's attack campaigns targeted banks and technology organizations in Saudi Arabia with phishing emails that included weaponized Microsoft Excel attachments.
Mimikatz performs credential dumping to obtain account and password information useful in gaining access to additional systems and enterprise network resources. It contains functionality to acquire information about credentials in many ways, including from DPAPI.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential stealer used by OilRig for harvesting credentials from compromised systems.
Tool used to dump passwords from web browsers.
A browser credential theft tool used in phishing campaigns.
Browser credential theft tool (32- and 64-bit DLL variants observed) that dumps saved website login credentials from Chrome, Firefox, and Internet Explorer; reported as exclusively used by APT34 in FireEye’s tracking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.