Adversaries may directly collect unsecured credentials stored or passed through user communication services.

Tactics
TA0006

Sub-technique of
T1552


See: MITRE ATT&CK