PinchDuke steals credentials from compromised hosts. PinchDuke's credential stealing functionality is believed to be based on the source code of the Pinch credential stealing malware (also known as LdPinch). Credentials targeted by PinchDuke include ones associated with The Bat!, Yahoo!, Mail.ru, Passport.Net, Google Talk, Netscape Navigator, Mozilla Firefox, Mozilla Thunderbird, Internet Explorer, Microsoft Outlook, WinInet Credential Cache, and Lightweight Directory Access Protocol (LDAP).
|Enterprise||T1005||Data from Local System|
|Enterprise||T1083||File and Directory Discovery|
|Enterprise||T1071||Standard Application Layer Protocol|
|Enterprise||T1082||System Information Discovery|
Groups That Use This Software