Skip to main content
Mallory
Back to malware
MalwareRansomwareUsed by 5 actors

WebBrowserPassView

WebBrowserPassView is a NirSoft credential-dumping utility used to extract usernames and passwords saved in web browsers on Windows systems. The provided content consistently describes it as a browser credential theft or password recovery tool that can dump browser-stored credentials, including via command-line execution and optional output to a file path specified with the /stext argument. It is also described as closed source, which limits easy modification compared with open-source alternatives such as LaZagne.

Across the cited reporting, WebBrowserPassView is used by multiple threat actors and intrusion sets as post-compromise credential access tooling. Kimsuky is repeatedly reported to have used NirSoft WebBrowserPassView to dump passwords from victims, including alongside malicious browser extensions used to steal passwords and cookies. Cisco Talos also reported its use in an intrusion at a Taiwanese government-affiliated research institute attributed with medium confidence to APT41, where the actor used WebBrowserPassView together with Mimikatz and other tooling to harvest credentials after initial access. Another Talos report describes a Kimsuky campaign in which a trojanized WebBrowserPassView v2.11 payload was injected to harvest browser credentials and write them to disk for later exfiltration. Additional reporting in the content states that Lazarus-linked activity downloaded, decrypted, and executed WebBrowserPassView to extract browser-related credentials and exfiltrate them with system information to a C2 server. The tool is also mentioned in ransomware and cybercrime intrusions, including Qilin affiliate activity and campaigns targeting trucking and logistics companies, where it was deployed after initial access for credential harvesting.

Behaviorally, the content ties WebBrowserPassView to browser credential dumping from fixed browser storage locations and to MITRE ATT&CK browser credential access activity. Detection-oriented reporting notes that successful extraction may not be reliably confirmed from logs unless the tool saves output to a file, and recommends monitoring process creation and file-access telemetry around browser credential stores. High-confidence indicators directly mentioned in the content include execution as WebBrowserPassView.exe and use of the /stext argument to write extracted credentials to a specified file.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
GopherWhisper

WebBrowserPassView, a NirSoft tool that extracts stored web browser credentials to the file path specified with the /stext argument.

Lazarus

Credential Theft: WebBrowserPassView is downloaded, decrypted and executed to extract browser-related credentials. Those credentials, together with system information, are exfiltrated to the command-and-control (C2) server.

via gen insights research bloggendigital.com
Malteiro

Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.

via mitre attackattack.mitre.org
Kimsuky

Kimsuky has also used Nirsoft's WebBrowserPassView tool to dump the passwords obtained from victims.

via mitre attackattack.mitre.org
APT41

The actor uses Mimikatz to harvest the hashes from the lsass process address space and WebBrowserPassView to get all credentials stored in the web browsers.

via talos intelligence blogblog.talosintelligence.com
MITRE ATT&CK

Techniques & procedures

8 distinct techniques documented for this family, organized by ATT&CK tactic.

T1588.002ToolEvidence3

GopherWhisper uses the publicly available WebBrowserPassView.

Initial Access

1 technique
T1078Valid AccountsEvidence1

“the attackers are prioritizing persistent access and credential theft… WebBrowserPassView… reveals the passwords stored by multiple web browsers.”

Persistence

1 technique
T1078Valid AccountsEvidence1

“the attackers are prioritizing persistent access and credential theft… WebBrowserPassView… reveals the passwords stored by multiple web browsers.”

T1078Valid AccountsEvidence1

“the attackers are prioritizing persistent access and credential theft… WebBrowserPassView… reveals the passwords stored by multiple web browsers.”

T1134.002Create Process with TokenEvidence2

rp.exe can execute a process using the same methods as runas.

Stealth

2 techniques
T1078Valid AccountsEvidence1

“the attackers are prioritizing persistent access and credential theft… WebBrowserPassView… reveals the passwords stored by multiple web browsers.”

T1134.002Create Process with TokenEvidence2

rp.exe can execute a process using the same methods as runas.

Credential Access

4 techniques
T1003OS Credential DumpingEvidence2

Credential Access [TA0006]... Tools such as Mimikatz, Lazagne, and WebBrowserPassView remain popular and prominent.

T1539Steal Web Session CookieEvidence1

WebBrowserPassView is a free password recovery tool that reveals the passwords stored by IE, Mozilla Firefox, Google Chrome, and Opera.

T1555Credentials from Password StoresEvidence8

WebBrowserPassView is a free password recovery tool that reveals the passwords stored by IE, Mozilla Firefox, Google Chrome, and Opera.

T1555.003Credentials from Web BrowsersEvidence7

WebBrowserPassView can gather credentials from a number of browsers.

T1105Ingress Tool TransferEvidence1

“ScreenConnect would then be used to download an additional attacker toolset.”

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app6 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping8

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.