Braodo is a stealer malware family associated in the provided content with credential theft and screen capture on Windows systems. The content states that Braodo commonly uses taskkill to terminate browser processes including chrome.exe, firefox.exe, brave.exe, opera.exe, msedge.exe, and chromium.exe in order to unlock files containing sensitive information such as saved passwords and login data. It is also described as copying Google Chrome credential store files, specifically "Local State" and "Login Data," into temporary directories, where these files may contain encrypted saved passwords and login session details. Additional behavior directly attributed to Braodo includes creating files in temporary folders containing passwords, cookies, saved login account information, and master key material prior to exfiltration, as well as capturing screenshots of the victim desktop and writing image files such as screenshot.png, screenshot.jpg, or screenshot.bmp in temp paths. The content ties these behaviors to MITRE ATT&CK techniques T1555.003 (Credentials from Web Browsers), T1113 (Screen Capture), T1560 (archived in temp dir dataset context), and T1562.001 (Disable or Modify Tools). High-confidence indicators and artifacts mentioned in the content include browser process termination via taskkill, temp-path file activity involving Chrome "Local State" and "Login Data," credential-related filenames such as login*, pass*, cookie*, and master_key*, and screenshot files created under \temp. The provided material is detection- and simulation-focused and does not directly identify a specific threat actor, industry targeting, or real-world campaign beyond associating the malware with credential theft and data collection activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-stealing malware that forcefully closes browsers such as Chrome, Edge, and Firefox to unlock files containing sensitive information like passwords and login data.
Braodo is described as a stealer malware that copies Chrome Local State and Login Data files into temporary folders in order to access encrypted browser credentials such as saved passwords and login session details.
Credential-stealing malware that collects passwords, cookies, and saved login information from web browsers and applications, stores the stolen data in temporary folders, and then exfiltrates it.
A stealer malware that captures screenshots of the victim's desktop and saves screen capture files, including in temporary folders, as part of data theft activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.