CredRaptor is a custom password-stealing tool associated with Sandworm Team, also referred to in reporting on the related TeleBots activity cluster. It has been in use since at least 2016 and is described as a bespoke credential theft utility rather than a general-purpose remote access platform. Its primary role is harvesting stored credentials from victim systems to support follow-on intrusion activity.
CredRaptor is known to collect saved passwords from multiple internet browsers. Additional reporting ties the tool to broader credential harvesting against applications beyond browsers, including Outlook and FTP clients, indicating a focus on extracting locally stored authentication material from common user software. This capability aligns with Sandworm and TeleBots operations in which credential access supported espionage, disruptive activity, and lateral movement within compromised environments.
The malware has been linked to the Sandworm/TeleBots ecosystem that has targeted Ukrainian organizations and has been associated with major disruptive campaigns, including operations connected to the Ukrainian power sector and other high-impact intrusions. CredRaptor appears to function as specialized supporting tooling within that ecosystem, complementing other credential theft methods such as modified Mimikatz variants.
High-confidence information supports CredRaptor as a custom credential stealer focused on browser-stored and other application-stored passwords on Windows systems. Specific initial infection or delivery vectors are not currently available from the supplied facts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team's CredRaptor tool can collect saved passwords from various internet browsers.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool used to collect saved passwords from various internet browsers.
CredRaptor is a custom password stealer used by TeleBots, capable of extracting credentials from browsers, email clients, FTP clients, and Windows Vault, aiding lateral movement and further compromise.
Tool that collects saved passwords from various internet browsers.
Tool used to collect saved passwords from various internet browsers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.