FOXGRABBER is a command-line credential-harvesting utility used to collect Firefox credential files from remote systems. It has been observed in intrusions associated with the financially motivated UNC2447 cluster and has also been reported in DARKSIDE ransomware intrusions. In the UNC2447 activity described by Mandiant, FOXGRABBER appeared alongside tooling such as WARPRISM and Cobalt Strike BEACON in campaigns that involved exploitation of SonicWall SMA 100 Series devices via CVE-2021-20016 and, in some cases, deployment of SOMBRAT and FIVEHANDS ransomware. A reported development artifact for FOXGRABBER is the PDB path C:\Users\kolobko\Source\Repos\grabff\obj\Debug\grabff.pdb. High-confidence behavior directly stated in the source is limited to harvesting Firefox credential files from remote systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FOXGRABBER is a command line utility used to harvest FireFox credential files from remote systems.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.