Threat actors and malware are continuing to harvest credentials from files, configuration stores, and application artifacts on compromised systems, a technique tracked as MITRE ATT&CK T1552.001. Common targets include browser password stores, email and chat clients, FTP/VPN/SSH tools, cloud credential files, and infrastructure secrets such as Docker or Kubernetes tokens. MITRE’s mappings show groups including Fox Kitten and FIN13 combining this activity with broader credential theft such as LSASS dumping, NTDS.dit extraction, registry hive theft, and collection of KeePass databases after gaining access through exploited public-facing applications, VPN appliances, remote services, or default credentials.
Defenders are also tracking this behavior in enterprise tools that store access secrets locally. Splunk published a Windows analytic that flags Security Event ID 4663 when any process other than winscp.exe accesses the WinSCP configuration security folder, which may contain SSH and FTP credentials, passwords, and private key references. The detection is intended to catch possible credential theft, including activity linked to information stealers such as Phantom Stealer, and Splunk advises investigators to review the accessing process, its parent process, and related network activity while accounting for benign access from backup or antivirus software.

Get the actors, campaigns, and ATT&CK mapping behind it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.