Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1185 Browser Session Hijacking |
MalwareTrickBot | TrickBot uses web injects and browser redirection to trick the user into providing their login credentials on a fake or modified web page. |
| T1185 Browser Session Hijacking |
MalwareUrsnif | Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords). |
| T1185 Browser Session Hijacking |
MalwareTRANSLATEXT | TRANSLATEXT has the ability to use form-grabbing and event-listening to extract data from web data forms. |
| T1185 Browser Session Hijacking |
MalwareIcedID | IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser. |
| T1185 Browser Session Hijacking |
MalwareChaes | Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts. |
| T1185 Browser Session Hijacking |
MalwareGrandoreiro | Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields. |
| T1185 Browser Session Hijacking |
MalwareXLoader | XLoader can conduct form grabbing, steal cookies, and extract data from HTTP sessions. |
| T1185 Browser Session Hijacking |
MalwareCobalt Strike | Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates. |
| T1185 Browser Session Hijacking |
MalwareCarberp | Carberp has captured credentials when a user performs login through a SSL session. |
| T1185 Browser Session Hijacking |
MalwareMelcoz | Melcoz can monitor the victim's browser for online banking sessions and display an overlay window to manipulate the session in the background. |
| T1185 Browser Session Hijacking |
MalwareAgent Tesla | Agent Tesla has the ability to use form-grabbing to extract data from web data forms. |
| T1185 Browser Session Hijacking |
MalwareQakBot | QakBot can use advanced web injects to steal web banking credentials. |
| T1185 Browser Session Hijacking |
MalwareDridex | Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies. |
| T1185 Browser Session Hijacking |
Toolevilginx2 | evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions. |
| T1185 Browser Session Hijacking |
MalwareKali365 | Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.