KeeThief is an open-source credential theft tool targeting the KeePass password manager. The provided content describes it as a PowerShell-based script used with a .NET assembly, KeeTheft.dll, to access, extract, and decrypt credentials stored by KeePass, including obtaining the master password and/or plaintext credentials from memory after the password database is unlocked. It is explicitly referenced as a tool for stealing credentials from third-party password managers and as part of credential access activity against KeePass.
The content associates KeeThief with Operation Wocao, where threat actors obtained and used open-source tools including KeeThief to access password manager credentials. A DHS/CISA TLP:WHITE report cited in the content describes an Iranian-based cyber actor targeting U.S. organizations in the information technology, government, healthcare, financial, and insurance sectors, and states that the actor used a PowerShell script from the KeeThief project to decrypt KeePass databases and steal credentials. In that reporting, the malicious script kee.ps1 (SHA256: 913ee2b048093162ff54dca050024f07200cdeaf13ffd56c449acb9e6d5fbda0) loads KeeTheft.dll (SHA256: 10836bda2d6a10791eb9541ad9ef1cb608aa9905766c28037950664cd64c6334) at runtime. The content also notes Harmj0y in connection with KeeThief.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Adversaries may acquire user credentials from password managers by extracting the master password and/or plain-text credentials from memory. [FoxIT Wocao December 2019] [Github KeeThief]
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple groups are described as using credential theft tools including Mimikatz, pwdump, gsecdump, Windows Credential Editor, LaZagne, KeeThief, ChromePass, and Nirsoft WebBrowserPassView.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KeeThief is referenced as a tool used to extract master passwords and/or plaintext credentials from password managers, particularly from memory after the password database is unlocked.
Credential theft tool associated with extracting credentials from KeePass/password manager environments (referenced as obtained/used in the operation).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.