T1552.001

Unsecured Credentials: Credentials In Files

discovered 2025-08-12

Scans Desktop, Downloads, and Documents for GitHub backup codes, Discord tokens, crypto wallet files, and sensitive documents matching keyword+extension patterns (English and French keywords). Extracts BIP-39 seed phrases from MetaMask/Exodus wallet files.

View on MITRE ATT&CK

Seen in packages

Campaigns