Description

The Password Recovery feature in malware is engineered to retrieve stored passwords from a variety of sources on the compromised system. Unlike brute-force or dictionary attacks that attempt to guess passwords, this feature targets saved credentials in browsers, email clients, and even software applications. The malware may scan cookies, encrypted password vaults, and even specific registry entries to recover these hidden gems of authentication data. Once harvested, the credentials can be used for privilege escalation, unauthorized access to sensitive accounts, or even financial fraud. The Password Recovery feature thus serves a critical role in the malware's arsenal, enabling the attacker to extend their reach within the compromised system and across linked networks or accounts, all while bypassing traditional methods of authentication.


Categories Lateral Movements, Privilege Escalation, Credentials
Dangerousness High

Existing Techniques

Associated with Releases

Version Origins Authors Languages Release Date
acid Drop 1.5 logoacid Drop 1.5 Unknown ๐Ÿดโ€โ˜ ๏ธ acid_alchemy Visual Basic 6 (VB6) Apr, 2004
Infector NG 2004 2.1.0 logoInfector NG 2004 2.1.0 Belgium ๐Ÿ‡ง๐Ÿ‡ช, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง fc , Infiltration Delphi May, 2004
Optix Pro 1.33 logoOptix Pro 1.33 Unknown ๐Ÿดโ€โ˜ ๏ธ s13az3 Delphi Aug, 2004
Beast 2.07 logoBeast 2.07 Romania ๐Ÿ‡ท๐Ÿ‡ด Tataye Delphi Aug, 2004
Flux 1.0 logoFlux 1.0 Unknown ๐Ÿดโ€โ˜ ๏ธ Gargamel C++ Aug, 2004
CIA 1.3 logoCIA 1.3 England ๐Ÿด๓ ง๓ ข๓ ฅ๓ ฎ๓ ง๓ ฟ Alchemist Visual Basic 6 (VB6) Dec, 2004
ProAgent 2.0 logoProAgent 2.0 Turkey ๐Ÿ‡น๐Ÿ‡ท ATmaCA Borland C++ Mar, 2005
ProRat 1.9 logoProRat 1.9 Turkey ๐Ÿ‡น๐Ÿ‡ท HighLander , ATmaCA Borland C++ Mar, 2005
Y3K rat 2k5 RC 1.0 logoY3K rat 2k5 RC 1.0 Austria ๐Ÿ‡ฆ๐Ÿ‡น SHA Delphi Jun, 2005
Y3K rat 2k5 RC 1.1 logoY3K rat 2k5 RC 1.1 Austria ๐Ÿ‡ฆ๐Ÿ‡น SHA Delphi Nov, 2005
Turkojan 3.0 logoTurkojan 3.0 Turkey ๐Ÿ‡น๐Ÿ‡ท Fungus Delphi Sep, 2006
Bifrost 1.2.1 logoBifrost 1.2.1 Sweden ๐Ÿ‡ธ๐Ÿ‡ช ksv C++ Jan, 2007
Bandook 1.35 logoBandook 1.35 Lebanon ๐Ÿ‡ฑ๐Ÿ‡ง PrinceAli Delphi, C++ Apr, 2007
Poison Ivy 2.3.0 logoPoison Ivy 2.3.0 Sweden ๐Ÿ‡ธ๐Ÿ‡ช Shapeless Delphi, MASM Jun, 2007
Hav-Rat 1.3.2 logoHav-Rat 1.3.2 Sweden ๐Ÿ‡ธ๐Ÿ‡ช Havalito Delphi Jul, 2007
sharK 2.4.0 Fwb+ logosharK 2.4.0 Fwb+ Germany ๐Ÿ‡ฉ๐Ÿ‡ช sNiper109 , rockZ Visual Basic 6 (VB6) Aug, 2007
DARKMOON 4.11 Private Edition logoDARKMOON 4.11 Private Edition Spain ๐Ÿ‡ช๐Ÿ‡ธ shukisnike Delphi Aug, 2007
Bump-Rat 1.2 Beta logoBump-Rat 1.2 Beta France ๐Ÿ‡ซ๐Ÿ‡ท Scraniak Visual Basic 6 (VB6) Sep, 2007
Universal1337 V2 logoUniversal1337 V2 Unknown ๐Ÿดโ€โ˜ ๏ธ Eddy-K Visual Basic 6 (VB6) Sep, 2007
Poison Ivy 2.3.2 logoPoison Ivy 2.3.2 Sweden ๐Ÿ‡ธ๐Ÿ‡ช Shapeless Delphi, MASM Jan, 2008
Lost Door 1.0 logoLost Door 1.0 Tunisia ๐Ÿ‡น๐Ÿ‡ณ OussamiO Visual Basic 6 (VB6) Jan, 2008
ZombieRat 1.2 logoZombieRat 1.2 Romania ๐Ÿ‡ท๐Ÿ‡ด The Bo$$ Assembly, Delphi Jan, 2008
Lost Door 2.0 logoLost Door 2.0 Tunisia ๐Ÿ‡น๐Ÿ‡ณ OussamiO Visual Basic 6 (VB6) Feb, 2008
Turkojan 4 logoTurkojan 4 Turkey ๐Ÿ‡น๐Ÿ‡ท FยตNGยตยง Delphi Feb, 2008
Turkojan 4.0 logoTurkojan 4.0 Turkey ๐Ÿ‡น๐Ÿ‡ท Fungus Delphi Mar, 2008
Lost Door 2.2 logoLost Door 2.2 Tunisia ๐Ÿ‡น๐Ÿ‡ณ OussamiO Visual Basic 6 (VB6) May, 2008
Aero 2 logoAero 2 Unknown ๐Ÿดโ€โ˜ ๏ธ Gareth Delphi Oct, 2008
Lost Door 3.0 Stable logoLost Door 3.0 Stable Tunisia ๐Ÿ‡น๐Ÿ‡ณ OussamiO Visual Basic 6 (VB6) Mar, 2009
SynRAT 4.0.1 logoSynRAT 4.0.1 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Delphi May, 2009
Cerberus 1.0 Beta logoCerberus 1.0 Beta United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
Cerberus 1.01 Beta logoCerberus 1.01 Beta United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
Cerberus 1.02 Beta logoCerberus 1.02 Beta United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Aug, 2009
SynRAT 4.3.1-A-1 logoSynRAT 4.3.1-A-1 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Assembly, Delphi Aug, 2009
Apocalypse RAT 1.4 logoApocalypse RAT 1.4 Turkey ๐Ÿ‡น๐Ÿ‡ท ap0calypse Delphi Aug, 2009
Cerberus 1.03.4 logoCerberus 1.03.4 United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Sep, 2009
Spy-Net 2.6 logoSpy-Net 2.6 Brazil ๐Ÿ‡ง๐Ÿ‡ท Raphael Delphi Oct, 2009
DarkComet RAT 1.3 logoDarkComet RAT 1.3 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Nov, 2009
Cerberus 1.03.5 Beta logoCerberus 1.03.5 Beta United States ๐Ÿ‡บ๐Ÿ‡ธ, United Kingdom ๐Ÿ‡ฌ๐Ÿ‡ง Protocol , Steve10120 , 2sly , Sam Delphi Dec, 2009
DarkComet RAT 2.0 RC4 logoDarkComet RAT 2.0 RC4 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Delphi Mar, 2010
CyberGate 1.04.8 logoCyberGate 1.04.8 United States ๐Ÿ‡บ๐Ÿ‡ธ johnyk Delphi Apr, 2010
Lost Door 4.3.1 logoLost Door 4.3.1 Tunisia ๐Ÿ‡น๐Ÿ‡ณ OussamiO Visual Basic 6 (VB6) Apr, 2010
DarkComet RAT 2.0 RC7 logoDarkComet RAT 2.0 RC7 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Assembly, Delphi Jun, 2010
Schwarze Sonne 1.0 logoSchwarze Sonne 1.0 Unknown ๐Ÿดโ€โ˜ ๏ธ, Germany ๐Ÿ‡ฉ๐Ÿ‡ช, Turkey ๐Ÿ‡น๐Ÿ‡ท ap0calypse , Slayer616 , Counterstrikewi Delphi Jun, 2010
Lost Door 5.1 logoLost Door 5.1 Tunisia ๐Ÿ‡น๐Ÿ‡ณ OussamiO Visual Basic 6 (VB6) Oct, 2010
Xtreme RAT 2.9 logoXtreme RAT 2.9 Brazil ๐Ÿ‡ง๐Ÿ‡ท Raphael Delphi Jul, 2011
DarkComet RAT 5.3 logoDarkComet RAT 5.3 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Assembly, Delphi Jun, 2012
DarkComet RAT 5.3.1 logoDarkComet RAT 5.3.1 France ๐Ÿ‡ซ๐Ÿ‡ท DarkCoderSc Assembly, Delphi Jun, 2012
Bozok 1.4 logoBozok 1.4 Germany ๐Ÿ‡ฉ๐Ÿ‡ช, Turkey ๐Ÿ‡น๐Ÿ‡ท Slayer616 Delphi Aug, 2013
NjRat 0.7d logoNjRat 0.7d Kuwait ๐Ÿ‡ฐ๐Ÿ‡ผ njq8 VB .net Dec, 2013
Quasar 1.0 logoQuasar 1.0 Unknown ๐Ÿดโ€โ˜ ๏ธ MaxXor C# Aug, 2015