ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1185×

15 examples

TechniqueUsed byProcedure example
T1185
Browser Session Hijacking
MalwareTrickBot

TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page.

T1185
Browser Session Hijacking
MalwareUrsnif

Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords).

T1185
Browser Session Hijacking
MalwareTRANSLATEXT

TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms.

T1185
Browser Session Hijacking
MalwareIcedID

IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser.

T1185
Browser Session Hijacking
MalwareChaes

Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts.

T1185
Browser Session Hijacking
MalwareGrandoreiro

Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

T1185
Browser Session Hijacking
MalwareXLoader

XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions.

T1185
Browser Session Hijacking
MalwareCobalt Strike

Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates.

T1185
Browser Session Hijacking
MalwareCarberp

Carberp has captured credentials when a user performs login through a SSL session.

T1185
Browser Session Hijacking
MalwareMelcoz

Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background.

T1185
Browser Session Hijacking
MalwareAgent Tesla

Agent Tesla has the ability to use form-grabbing to extract data from web data forms.

T1185
Browser Session Hijacking
MalwareQakBot

QakBot can use advanced web injects to steal web banking credentials.

T1185
Browser Session Hijacking
MalwareDridex

Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies.

T1185
Browser Session Hijacking
Toolevilginx2

evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions.

T1185
Browser Session Hijacking
MalwareKali365

Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.