[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/credential-gathering-third-party-software/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/credential-gathering-third-party-software/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Credential Gathering From Third-Party Software

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 14 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Dor Attar](https://unit42.paloaltonetworks.com/author/dor-attar/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 8, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/)
  * [Credential theft](https://unit42.paloaltonetworks.com/tag/credential-theft/)
  * [Password stealer](https://unit42.paloaltonetworks.com/tag/password-stealer/)
  * [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/credential-gathering-third-party-software/?pdf=download&lg=en&_wpnonce=7052973960 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/credential-gathering-third-party-software/?pdf=print&lg=en&_wpnonce=7052973960 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Credential%20Gathering%20From%20Third-Party%20Software&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fcredential-gathering-third-party-software%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcredential-gathering-third-party-software%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcredential-gathering-third-party-software%2F&title=Credential%20Gathering%20From%20Third-Party%20Software "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcredential-gathering-third-party-software%2F&text=Credential%20Gathering%20From%20Third-Party%20Software "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcredential-gathering-third-party-software%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Credential%20Gathering%20From%20Third-Party%20Software%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fcredential-gathering-third-party-software%2F "Share in Mastodon")

## Executive Summary

There is a constant debate between usability and security in the software world. Many third-party programs can make their users' lives easier and save them time by storing their credentials. However, as it turns out, this convenience often comes at the price of poor security, causing the risk of password theft. Credentials gathered in this manner can then be used during an actual cyberattack.

In this article, we will explain the dangers of credential theft. We will examine some common third-party software scenarios related to credential gathering, looking into how passwords are stored, how they can be retrieved and how to monitor these actions based on real-world attack scenarios.

[Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) Customers are protected from such attacks using the Credential Gathering Protection Module released in Cortex 3.4 on Windows, Linux and MacOS agents.

|------------------------|-----------------------------------------------------------------------------------------|
| Related Unit 42 topics | [Credential harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/) |

## The Dangers of Credential Theft: How Attackers Can Expand Their Access

It is clear that credential theft is bad. However, it is important to emphasize the scale of the impact that credential theft can have.

[Many people tend to use the same password in different programs](https://www.enzoic.com/8-stats-on-password-reuse/) and rarely change their passwords. When the time comes to modify their passwords, many people follow a predictable pattern.

Thus, when attackers can get a password from one source, they can try to use it against other resources, including some that are more protected. So, for every program A that is well secured, the user could use the same password or pattern on program B that is less secure -- which could result in making program A less secure.

Furthermore, if it turns out that a person is using their operating system password in other less secure locations, a whole new world of possibilities is open to the attacker.

Let's say, for example, that person X uses the same password for his Windows account domain and a Linux FTP file server. In this scenario, person X uses the common program WinSCP to manage their files in the file server. Although WinSCP advises that saving passwords isn't recommended, person X accesses this file server every week, so they prefer to save time and save their password.
![The red box highlights the "Save password" option in WinSCP, which is specifically listed as "not recommended."](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image.png) Figure 1. Password saving is not recommended by WinSCP.

As we will demonstrate later in this blog, the user's password can easily be retrieved from where WinSCP stores it. An attacker who can get a foothold on X's personal computer can get their domain account password -- only because it is being saved insecurely. This is on top of the fact that the password is valid for connecting to the file server. This file server may contain files with sensitive information to which the attacker now has access. From there, the attacker can use tools like [BloodHound](https://attack.mitre.org/software/S0521) to estimate how far they can spread within an organization.

## Credential Gathering in Practice

### Software: WinSCP

[WinSCP](https://winscp.net/eng/index.php) is a popular SFTP client and FTP client for Microsoft Windows that is used to copy files between local Windows computers and remote servers using FTP, FTPS, SCP and SFTP.

#### Tested version:

5\.19.6 (Build 12002 2022-02-22)

#### Where are credentials stored?

WinSCP stores the encrypted user's password under the registry key HKCU\\software\\martin prikryl\\winscp 2\\sessions\\\<session\_name\> in a value called Password.

#### How can the credentials be recovered?

WinSCP performs symmetric mathematical operations on the bits of the user's passwords. It takes each byte of the password, computes the complement to 0xFF (11111111), and after that, XORs it with the byte **0xA3**(10100011).

The encryption process comprises finding the complement and performing the XOR one time. The password is then stored in the Password registry value. Since these mathematical operations are symmetric, all we need to do is perform the same two operations once again, in reverse order, to get the original value.

For example, let's take a commonly used password: Aa123456. This is how WinSCP will store this password: 1D3D6D6E6F68696A.

In Figure 2, we see the steps to decrypt the password:
![Steps to decrypt a password in WinSCP include performing the XOR with 0xA3 and finding the complement, as shown in the table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-1.png) Figure 2. Decrypting a password stored in WinSCP.

The password is saved along with the HostName and UserName. To get it from the Password registry value, we must find the index at the beginning of the password. This calculation is pretty easy -- depending on the WinSCP version, the first or third byte of the registry value is the length of the username, hostname and password, concatenated. The start index is the following byte to the length, and its value is multiplied by two. Both the length and the start index are encrypted in the same way.

The UserName and HostName are also saved on different registry values, so we know their length and value. All we do is decrypt the Password registry value from the index: start index + username length + hostname length to length, and we will get our password.
![The screenshot shows how to decrypt the Password registry value from the index in WinSCP: start index + username length + hostname length to length. The result is the password.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-2.png) Figure 3. Location of username, hostname and password, concatenated.

#### In the wild

We have seen the following script executed in multiple customer environments:
![A suspicious PowerShell script that Unit 42 has observed in multiple environments. The decoded script attempts to decrypt WinSCP passwords.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-3.png) Figure 4. Suspicious PowerShell with encoded command.

* \-enc stands for EncodedCommand, meaning that a base-64-encoded string is used as the command.

In the decoded script, we can see an attempt to decrypt WinSCP passwords:
![Decoded version of PowerShell script used for credential gathering.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-4.png) Figure 5. PowerShell script for extracting and decrypting WinSCP's passwords.

![Red boxes show how the Credential Gathering Protection module in Cortex XDR identifies a suspicious registry operation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-5.png) Figure 6. Cortex XDR prevented attempts to read passwords stored in WinSCP.

### Software: Git

#### Tested version:

2\.35.1.windows.2

#### Where are credentials stored?

Git allows for the use of both passwords and Personal Access Tokens (PATs).

When users want to save time by saving their Git credentials, they can do it using the following command:

git config credential.helper 'store'

Using this command, Git will save the user's credentials indefinitely on disk, in plain text.

Possible files containing passwords:

* \<userprofile\>\\.git-credentials
* \<userprofile\>\\.config\\git\\credentials

Git allows using PATs as credentials instead of the traditional use of passwords. These tokens are more modular, as any number of access tokens can be created, each with different permissions and expiration dates.

Although it is possible to control users' actions in a more modular and granular way, each associated with a specific PAT, anyone who has the user's PAT can view all repositories to which the user has access.

These tokens also appear in cleartext in the same files mentioned above.

#### How can the credentials be recovered?

Anyone who reads these files will see the username, password or token, and relevant Git repository **in plain text**.

### Software: RDCMan

#### Tested version:

2\.83

[RDCMan](https://docs.microsoft.com/en-us/sysinternals/downloads/rdcman) manages multiple remote desktop connections. It is useful for managing server labs where you need regular access to machines, such as automated check-in systems and data centers.

#### Where are credentials stored?

When a user decides to save a password for a session using RDCMan, the default configuration file will be %localappdata%\\Microsoft\\Remote Desktop Connection Manager\\RDCMan.settings

This file is an XML file that contains general metadata about each RDP connection.

Among the data, there is an XML tag called CredentialsProfiles, which has attracted our attention.

We can see that under this tag, there is another one called CredentialsProfiles, and inside there are credentialsProfile XML tags, with a Password tag.
![A red box highlights the contents of the Password tag in the credentialsProfile XML tags in RDCMan.settings](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-6.png) Figure 7. Looking at the XML tags in RDCMan.settings

#### How can the credentials be recovered?

To retrieve the password, we will have to execute commands in the context of the person using the RDCMan program. This is because the password is being saved using the DATA Protection API (DPAPI), which enables symmetric encryption and decryption of any kind of data using the functions [CryptProtectData](https://docs.microsoft.com/en-us/windows/win32/api/dpapi/nf-dpapi-cryptprotectdata) and [CryptUnprotectData](https://docs.microsoft.com/en-us/windows/win32/api/dpapi/nf-dpapi-cryptunprotectdata), respectively.

So, to get the password, we need to call the function CryptUnprotectData.

Usually, the only user who can decrypt the data is a user with the same login credentials as the user who encrypted the data.

Although gathering credentials from RDCMan requires an additional step from the attacker than was needed in some of our other examples -- running the software in the context of the relevant user -- there is great value to the result for the attacker. If the effort is successful, it's possible for the threat actor to get all the users and passwords for all of the machines that this specific user connects to.

Once the attacker is able to execute commands in the context of the user, all that remains in order to gather credentials is to:

1. Open the RDCMan.settings file and check for the password XML tag.
2. Decode the string in the tag with base64.
3. Call CryptUnprotectData with the decoded password string.
4. Decode the result using UTF-8 (or other relevant formats).
5. Remove unnecessary null characters.

Looking at the example above, the password saved in the file was:

AQAAANCMnd8BFdERjHoAwE/Cl+sBAAAA8/nnW5aFNUi0AKiTG4y9UQAAAAACAAAAAAAQZgAAAAEAACAAAADIjLLw0X4z9RDdWgPpqabLU7hTcJ1HVlFklpzX3eA14QAAAAAOgAAAAAIAACAAAAB01OvDCNCjaEhrq8J8hRm/SKycef7nR52ZkqcPLJqMsCAAAACg2htaeRsutDziS3FISeEAg3DsBpGxBGpPeWlUSVnXOkAAAAB5Tei9g5KWcVIhOKQ2cXxr5ONUOHMEEH5h3Lmp12mPlWaaZ6y8dGIVz8WnNKr4e73dhqNU8NyzI7RZBamS6DG6

And the decrypted password is Aa123456.
![The red box highlights the results of password decryption efforts that complete credential gathering targeting RDCMan.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-7.png) Figure 8. Recovering a password from RDCMan.

### Software: OpenVPN

#### Tested version:

2\.5.029

[OpenVPN](https://en.wikipedia.org/wiki/OpenVPN) is a virtual private network system that implements techniques to create secure point-to-point or site-to-site connections in routed or bridged configurations and remote access facilities.

#### Where are credentials stored?

OpenVPN stores the user's password under the registry key HKCU\\software\\openvpn-gui\\configs\\\<session\_name\> in a value called auth-data.

#### How can the credentials be recovered?

OpenVPN also uses the DPAPI mechanism, with the additional optional [entropy](https://docs.microsoft.com/en-us/windows/win32/api/dpapi/nf-dpapi-cryptunprotectdata#:~:text=the%20LocalFree%20function.-,%5Bin%2C%20optional%5D%20pOptionalEntropy,-A%20pointer%20to) parameter (which can be set to NULL).

When an optional entropy DATA\_BLOB structure was used in the encryption phase, that same DATA\_BLOB structure must be used for the decryption phase.

In the case of OpenVPN, the entropy is saved in a registry value called entropy. The entropy registry value is also stored in the path HKCU\\software\\openvpn-gui\\configs\\\<session\_name\>

So, calling CryptUnprotectData with the password from auth-data and entropy (from entropy) will give us the session password.

The entropy registry value contains an extra byte of 00, so we just need to omit it.
![Above, the PowerShell script for recovering an OpenVPN password. Below, the way auth-data and entropy registry values are shown via reg.exe](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-8.png) Figure 9. Above, the PowerShell script for recovering an OpenVPN password. Below, the way auth-data and entropy registry values are shown via reg.exe ([POC](https://github.com/flyinghuman/openvpnpasswordrecovery/blob/master/openvpn-passwords.ps1)).

### Software: Chromium-based Browsers

#### Tested version:

* Google Chrome -- Tested version: 103.0.5060.53 (Official Build) (64-bit)
* Microsoft Edge -- Tested version: 103.0.1264.37 (Official Build) (64-bit)
* Opera -- Tested version: 88.0.4412.53

The [Chromium projects](https://www.chromium.org/chromium-projects) include Chromium, the open-source project behind the Google Chrome browser.

In a typical usage routine, many people tend to save passwords while surfing the internet.
![The screenshot shows a redacted version of the screen that appears when checking stored passwords in Google Chrome settings.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-9.png) Figure 10. Passwords saved by Google Chrome Version 102.0.5005.115 (Official Build) (64-bit).

#### Where are credentials stored?

When using a Chromium-based browser, like Microsoft Edge, Opera or Google Chrome, passwords are located encrypted in an SQLite database file, usually called login data.

Each profile has a password database -- its login data file.

The key used to encrypt the passwords is located in the parent folder, in a JSON file called local state.

For example:

login data locations:

* Google Chrome: %localappdata%\\google\\**chrome**\\user data\\\<PROFILE\>\\login data
* Microsoft Edge: %localappdata%\\microsoft\\**edge**\\user data\\\<PROFILE\>\\login data
* Opera: %appdata%\\opera software\\**opera** **stable**\\\<PROFILE\>\\login data

local state locations:

* Google Chrome: %localappdata%\\google\\**chrome**\\user data\\local state
* Microsoft Edge: %localappdata%\\microsoft\\**edge**\\user data\\local state
* Opera: %appdata%\\opera software\\**opera stable**\\local state

#### How can the credentials be recovered?

Each password in the login data database is encrypted using the [Advanced Encryption Standard (AES)](https://en.wikipedia.org/wiki/Advanced_Encryption_Standard), with GCM mode. AES GCM is a symmetrical encryption method, so the same key is valid for both encryption and decryption. The AES algorithm uses a different key for every 128-bit block, which is based on the calculation of the previous block. For the first block, there is an option to use the Initialization Vector (IV).

To decrypt a password that a Chromium-based browser saves, we need to have:

1. The encrypted password.
2. The initialization vector.
3. The AES key.

Let's see how we can retrieve each of those:

A. The encrypted password.

Can be exported from the login data database -- the encrypted password is taken from the password\_value column, from the letter in the 15th position to the end -- 16 letters. \[15:-16\]

B. The initialization vector.

Located in the same password\_value field column, from the letter in the third position to the letter in the 15th position. \[3:15\]

C. The AES key.

Written in the local state JSON file, under keys os\_crypt and encrypted\_key, decoded with base64.

Chromium-based browsers save the AES key using the DPAPI mechanism, so to get it, we will have to decode it from base64 and use CryptUnprotectData in the user's context.

Example from Google Chrome:
![Example from Google Chrome of a password saved in the local state JSON file of Google Chrome. Visible phrases include os\_crypt, encrypted\_key and password\_manager.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-10.png) Figure 11. Password that is being saved in local state JSON file of Google Chrome.

It is being saved with a prefix of five letters at the beginning: DPAPI.
![The decoded password is shown. Highlighted in red at the beginning is a prefix of five letters: DPAPI](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-11.png) Figure 12. The decoded password that was saved in Google Chrome.

If the attacker is able to run in the context of the user, all that is necessary to complete gathering user credentials is:

1. Copy both login data and local state files.
2. Get the AES GCM key from the local state JSON file.
3. Decode (base64), decrypt (CryptUnprotectData) and remove the padding from the key.
4. Decrypt each password in the login data database, using the decrypted AES GCM key.

![A proof of concept for recovering passwords that were saved in Chrome - the screenshot shows the outcome of python\_Chrome\_pass.py, with sensitive information redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-12.png) Figure 13. POC for recovering passwords that were saved in Chrome.

You can read more about how to [extract Chrome passwords in Python](https://www.thepythoncode.com/article/extract-chrome-passwords-python).

#### In the wild

We have seen the following DLL running from excel.exe using regsvr32.exe with the following command line:

C:\\windows\\system32\\regsvr32.exe  
C:\\users\\\<username\>\\appdata\\local\\uolegxnwf\\kgnkudbadmpogg.dll

(SHA256 of kgnkudbadmpogg.dll: 6599FEE8C7ADF30A00889A7070600F472F8CEAD8EA4DD1A85E724ED15F2AED0F)

After a chain of events, the final payload was trying to access Microsoft Edge credentials files:

* The login data file (SQLite database file)  
  C:\\users\\\<username\>\\appdata\\local\\microsoft\\edge\\user data\\default\\login data

* The local state file (contains the encryption key)  
  C:\\users\\\<username\>\\appdata\\local\\microsoft\\edge\\user data\\local state

![Red boxes highlight the Credential Gathering module and the key file paths observed.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-13.png) Figure 14. Cortex XDR detected attempts to read passwords saved in the Microsoft Edge browser.

### Software: Firefox Browser

#### Tested version:

Firefox Version 101.0.1 (64-bit)

The password-saving behavior pattern is also relevant when using other browsers, such as Mozilla Firefox.
![Screenshot of stored passwords in Mozilla Firefox with key info redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-14.png) Figure 15. Passwords that are being saved by Firefox Version 101.0.1 (64-bit).

#### Where are credentials stored?

Similar to Chromium-based browsers, in the Mozilla Firefox browser, each profile also has its own password file.

This file is called logins.json and is located in %appdata%\\mozilla\\firefox\\profiles\\\<PROFILE\>\\logins.json

Both username and password are saved encrypted.
![The screenshot shows encryptedUsername and encryptedPassword, among other logins data](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-15.png) Figure 16. Password saved in the logins.json file of Firefox.

#### How can the credentials be recovered?

Each username and password in the logins.json file is encrypted using the [PKCS #11](https://en.wikipedia.org/wiki/PKCS_11) cryptography standard. Firefox has developed the NSS library to adopt this standard into its browser (nss3.dll).

[NSS stores private keys](https://wiki.mozilla.org/NSS_Shared_DB) in a file called key3.db or key4.db, depending on the NSS version.

To retrieve the user's passwords, the attacker will have to access one of these files and the logins.json file.

So, if the attacker can gain access to run on the same machine, the process of stealing the passwords will be:

1. The attacker copies the logins.json file.
2. Loads the NSS library (nss3.dll)
3. Decodes (base64) the encryptedUsername and encryptedPassword from the copy of logins.json.
4. Stores each of the inputs in a [SecItem](https://mozilla.github.io/python-nss-docs/nss.nss.SecItem-class.html)) object, which is later used throughout NSS to pass blocks of binary data back and forth.
5. Creates SecItem objects for output.
6. Decrypts each encryptedUsername and encryptedPassword input object, and stores the data in the new SecItem output objects, using the PK11 decryption function from nss3.dll.

Unlike the case of Chromium-based browsers, the attacker doesn't have to run in a user's context to get the person's passwords, but can take advantage of any user who has permission to access the file system profile of the target user.
![Red boxes highlight where User S is able to gather credentials from User D.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-16.png) Figure 17. User S got passwords belonging to user D that were saved in Firefox profile 2. (POC)

#### In the wild

We have seen the following script executed:
![A suspicious obfuscated PowerShell script that attempts to gather credentials from Mozilla Firefox.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-17.png) Figure 18. Suspicious obfuscated PowerShell script.

After decoding:
![The deobuscated PowerShell script reveals a series of links as shown](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-18.png) Figure 19. De-obfuscated PowerShell script.

The script:

1. Creates the folder %localappdata%\\ujXgAD
2. Tries to create Invoke-WebRequest for each of the links in $Links, downloads a DLL and saves it in the folder mentioned in step A with the name rRXqwGvGNR.wTj
3. Breaks after the first successful execution.

Next, we saw that a DLL was created on the endpoint and regsvr32.exe was used with the following command line:

C:\\WINDOWS\\system32\\regsvr32.exe  
C:\\Users\\\<USERNAME\>\\AppData\\Local\\Temp\\..\\ujXgAD\\rRXqwGvGNR.wTj

Note that the path has an evasion in it: By using \\..\\ to go back to the Local folder, the attacker avoids accessing it directly.

After using regsvr32.exe:

A. The DLL copies itself to a random folder with a random name, with a DLL extension:  
C:\\Users\\\<USERNAME\>\\AppData\\Local\\\<random\_folder\_name\>\\\<random\_dll\_name\>.dll

B. The DLL executes a couple of discovery commands:

1. 1. systeminfo -- To list machine information.
   2. ipconfig /all -- To list all network interfaces on the machine.
   3. nltest.exe /dclist: -- To list all domain controllers in the domain.

C. The DLL creates and executes two files based on certutil.exe with random names:

1. One of them has a new random name but is still signed by Microsoft.
2. The other one is a mangled version of certutil -- keeping the original name, but with different functionality, and no signature.

D. Step C above is done twice.

Unsigned file SHA256:  
A88C344F3F80F8A3EA2E9BA0687FEBCEE2A730FD9AC037D54C4FD21C0AB91039

Certutil SHA256 - **Note that this file is benign** :  
D252235AA420B91C38BFEEC4F1C3F3434BC853D04635453648B26B2947352889

The unsigned certutil.exe then tries to access password files, both for Chromium-based and Firefox-based browsers.

When checking the links from Figure 19, only two links worked:
![DLLs downloaded as part of this credential gathering attack include lw1JF63zARLUV8UwpwGnWpgg.dll and RwuuPYoVei7FkJB.dll](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-19.png) Figure 20. DLLs that we were able to download.

* First downloaded DLL:  
  hxxps://www\[.\]yell\[.\]ge/nav\_logo/AEnTP/  
  Downloaded filename: RwuuPYoVei7FkJB.dll  
  (SHA256: A1D513E4A5C83895E5769C994C4D319959EF5AE3F679CE6C0C5211B5BECA7695)

* Second downloaded DLL:  
  hxxps://yakosurf\[.\]com/wp-includes/S/  
  Downloaded filename: lw1JF63zARLUV8UwpwGnWpgg.dll  
  (SHA256: 1B8638333751EFCB6B5332C801C11DF0DE3D7077C6ACEA1D663C0302519D7172)

In both cases, it is actually the same DLL, except for a small difference that changes the SHA256 hash.

Looking into this sample, we identified the first DLL as part of the [Emotet](https://unit42.paloaltonetworks.com/tag/emotet/) malware family.
![Red boxes highlight how the Credential Gathering Protection module identifies key file paths.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-20.png) Figure 21. Cortex XDR prevented attempts to read passwords saved in the Firefox browser.

Cortex XDR stops this operation **synchronously**, so the next attack stages are not performed. This malware tries to read passwords in this order: first Firefox, then Microsoft Edge and later, Google Chrome.

For the demonstration, we will illustrate Cortex XDR with report mode. We will see that the Credential Gathering Protection Module also detects attempts to read Chromium-based browsers' saved passwords.
![Red boxes how the Cortex XDR Credential Gathering Protection module identifies key file paths.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-21.png) Figure 22. Cortex XDR detected attempts to read passwords saved in the Microsoft Edge browser. ![Red boxes highlight how the Credential Gathering Module identifies key file paths.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-22.png) Figure 23. Cortex XDR detected attempts to read passwords saved in the Google Chrome browser.

## Emotet?

Since we saw two different cases involving Emotet, we looked a bit deeper into this malware family and its methods for third-party credential gathering. We saw that sometimes malware does not even need to implement all the logical conditions on its own. It can just wrap existing tools, like the [WebBrowserPassView](https://www.nirsoft.net/utils/web_browser_password.html) Nirsoft tool, to reveal the passwords stored by the web browsers.
![WebBrowserPassView.exe shows usernames, passwords and the file path that stores each of them. While sensitive info is redacted, the web browser from which each password was taken is visible.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-23.png) Figure 24. WebBrowserPassView.exe shows usernames, passwords and the file path that stores each of them.

We can see the login data file for Chromium-based browsers, and the logins.json file for the Firefox browser.
![Red boxes highlight how the Credential Gathering Protection module identifies key file paths.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/09/word-image-24.png) Figure 25. Cortex XDR prevented attempts to read browsers' saved passwords by WebBrowserPassView.exe.

## Conclusion

It turns out that the way certain third-party software stores credentials is less secure than we thought. Most of these programs store the user's credentials on the local disk, via file or registry values. This fact can be the one weak spot in the chain that attackers wish to find, giving them the access to perform an attack against an organization.

Palo Alto Networks customers using Cortex XDR receive protections using the new Credential Gathering Protection Module for the scenarios described above as well as other credential gathering techniques not mentioned in this write-up. Additional layers of protection -- including Local Analysis, Behavioral Threat Protection, BIOC and Analytics BIOCs rules -- are also available.

Palo Alto Networks customers that use [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) receive protections from tools implementing these credential gathering attempts.

Nirsoft tools are marked as grayware in WildFire and are blocked by the XDR Agent.

## Indicators of Compromise

|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Unauthorized access to the following registry values**                                                                                                                                                               |
| \* HKCU\\software\\martin prikryl\\winscp 2\\sessions\\\<session\_name\>\\Password \* HKCU\\software\\openvpn-gui\\configs\\\<session\_name\>\\auth-data \* HKCU\\software\\openvpn-gui\\configs\\\<session\_name\>\\entropy |

|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Unauthorized access to the following files**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| \* \<userprofile\>\\.git-credentials \* \<userprofile\>\\.config\\git\\credentials \* %localappdata%\\Microsoft\\Remote Desktop Connection Manager\\RDCMan.settings \* %localappdata%\\google\\chrome\\user data\\\<PROFILE\>\\login data \* %localappdata%\\microsoft\\edge\\user data\\\<PROFILE\>\\login data \* %appdata%\\opera software\\opera stable\\\<PROFILE\>\\login data \* %localappdata%\\google\\chrome\\user data\\local state \* %localappdata%\\microsoft\\edge\\user data\\local state \* %appdata%\\opera software\\opera stable\\local state \* %appdata%\\mozilla\\firefox\\profiles\\\<PROFILE\>\\logins.json \* %appdata%\\mozilla\\firefox\\profiles\\\<PROFILE\>\\key\<3/4\>.json |

|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Malicious hashes**                                                                                                                                                                                                                                                       |
| 6599FEE8C7ADF30A00889A7070600F472F8CEAD8EA4DD1A85E724ED15F2AED0F  A88C344F3F80F8A3EA2E9BA0687FEBCEE2A730FD9AC037D54C4FD21C0AB91039 A1D513E4A5C83895E5769C994C4D319959EF5AE3F679CE6C0C5211B5BECA7695 1B8638333751EFCB6B5332C801C11DF0DE3D7077C6ACEA1D663C0302519D7172 |

## Additional Resources

* [Detecting Credential Stealing with Cortex XDR](https://www.paloaltonetworks.com/blog/security-operations/detecting-credential-stealing-with-cortex-xdr/)
* [git-credential-store Documentation](https://git-scm.com/docs/git-credential-store)
* [Git Tools - Credential Storage](https://git-scm.com/book/en/v2/Git-Tools-Credential-Storage)
* [GitHub Docs: Creating a Personal Access Token](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/creating-a-personal-access-token)
* [CryptUnprotectData function (dpapi.h)](https://docs.microsoft.com/en-us/windows/win32/api/dpapi/nf-dpapi-cryptunprotectdata)
* [How Emotet is altering techniques in response to Microsoft's tightening of Workplace macro safety](https://blingeach.com/how-emotet-is-altering-techniques-in-response-to-microsofts-tightening-of-workplace-macro-safety/)
* [How to crack Firefox passwords with Python](https://medium.com/geekculture/how-to-hack-firefox-passwords-with-python-a394abf18016)
* [servo/nss](https://github.com/servo/nss/blob/master/lib/pk11wrap/pk11sdr.c)
  Back to top

### Tags

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")
* [Credential theft](https://unit42.paloaltonetworks.com/tag/credential-theft/ "credential theft")
* [Password stealer](https://unit42.paloaltonetworks.com/tag/password-stealer/ "password stealer")
* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Mirai Variant MooBot Targeting D-Link Devices](https://unit42.paloaltonetworks.com/moobot-d-link-devices/ "Mirai Variant MooBot Targeting D-Link Devices")

### Table of Contents

* 

### Related Articles

* [The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version](https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/ "article - table of contents")
* [The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)](https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/ "article - table of contents")
* ["Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack (Updated November 26)](https://unit42.paloaltonetworks.com/npm-supply-chain-attack/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")  
  ![Pictorial representation of Token-jacking. A person types on a laptop with multiple digital interface elements projected, including an "AI" icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1246251272-2-786x369.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 6, 2026 [#### Token Jacking: Cybercriminals Could Be Stealing Your AI Resources](https://unit42.paloaltonetworks.com/ai-token-jacking/)

* [AI API](https://unit42.paloaltonetworks.com/tag/ai-api/ "AI API")

* [AI gateway](https://unit42.paloaltonetworks.com/tag/ai-gateway/ "AI gateway")

* [API keys](https://unit42.paloaltonetworks.com/tag/api-keys/ "API keys")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-token-jacking/ "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources")  
  ![Pictorial representation of malware bypassing DNS and communicating directly to IP addresses. Futuristic digital cityscape with glowing blue and orange geometric structures, resembling skyscrapers.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_DNS_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 4, 2026 [#### Almost Half of Malware Samples Communicate Direct to IP](https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/)

* [Command and Control](https://unit42.paloaltonetworks.com/tag/command-and-control/ "Command and Control")

* [D2IP](https://unit42.paloaltonetworks.com/tag/d2ip/ "D2IP")

* [Exfiltration](https://unit42.paloaltonetworks.com/tag/exfiltration/ "exfiltration")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/ "Almost Half of Malware Samples Communicate Direct to IP")  
  ![Pictorial representation of passwordless authentication. East Asian woman examining data on multiple screens in a high-tech environment, surrounded by digital graphics and code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 3, 2026 [#### Pass the Passkey: A Novel Attack Surface in Passwordless Authentication](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/)

* [Google authenticator](https://unit42.paloaltonetworks.com/tag/google-authenticator/ "google authenticator")

* [Google Chrome](https://unit42.paloaltonetworks.com/tag/google-chrome/ "Google Chrome")

* [Google Cloud](https://unit42.paloaltonetworks.com/tag/google-cloud/ "Google Cloud")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/ "Pass the Passkey: A Novel Attack Surface in Passwordless Authentication")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
