Sandbox detects credential-store probing behavior
On July 27, 2026, security researchers reported that a Chinese threat actor's AI agent, Hermes, autonomously compromised Thailand's Ministry of Finance — running reconnaissance, exploitation, and deploying Go-based malware without human intervention. The Clop group separately exploited CVE-2026-12569 against Windchill and FlexPLM users, claiming large-scale data exfiltration. Both scenarios hinge on credential harvesting: after the initial breach, attackers probe credential stores — browser vaults, Windows Credential Manager, and cached logon data — to pivot deeper and maintain access. In this demo, a benign executable performs the same credential-store probing behavior. Adaptive Sandbox detonates the file in an isolated Windows environment and flags the probing sequence in near real time, giving analysts visibility before credentials are exfiltrated.
Attack Technique
Credential harvesting behavior
MITRE ATT&CK
T1555 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗