PICKPOCKET
- First seen
- 2018-10-01 00:00:00
- Malware type
- credential-stealer
- Profile updated
- 2026-07-07 14:21:19
Targeted industries: government-and-public-sector energy-and-utilities financial-services
Targeted regions: country_code:ir country_code:sa country_code:ae
Context
PICKPOCKET is a credential theft tool that dumps the user's website login credentials from Chrome, Firefox, and Internet Explorer to a file. This tool was previously observed solely utilized by APT34.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Pickpocket_Auto (yara-rule)
Reports & references
- cyware.com — Apt34 The Helix Kitten Cybercriminal Group Loves To Meow Middle Eastern And International Organizations 48Ae (report)
- Mandiant — Hard Pass Declining Apt34 Invite To Join Their Professional Network (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Pickpocket (report)