ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1539×

20 examples

TechniqueUsed byProcedure example
T1539
Steal Web Session Cookie
MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server.

T1539
Steal Web Session Cookie
MalwareLumma Stealer

Lumma Stealer has harvested cookies from various browsers.

T1539
Steal Web Session Cookie
MalwareDarkGate

DarkGate attempts to steal Opera cookies, if present, after terminating the related process.

T1539
Steal Web Session Cookie
MalwareChaes

Chaes has used a script that extracts the web session cookie and sends it to the C2 server.

T1539
Steal Web Session Cookie
MalwareLODEINFO

LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies.

T1539
Steal Web Session Cookie
MalwareEVILNUM

EVILNUM can harvest cookies and upload them to the C2 server.

T1539
Steal Web Session Cookie
MalwareGlassWorm

GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers.

T1539
Steal Web Session Cookie
MalwareSpica

Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers.

T1539
Steal Web Session Cookie
MalwareBLUELIGHT

BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers.

T1539
Steal Web Session Cookie
MalwareRedLine Stealer

RedLine Stealer has stolen browser cookies and settings.

T1539
Steal Web Session Cookie
MalwareGrandoreiro

Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device.

T1539
Steal Web Session Cookie
MalwareXLoader

XLoader can capture web session cookies and session information from victim browsers.

T1539
Steal Web Session Cookie
MalwareMgBot

MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers.

T1539
Steal Web Session Cookie
MalwareTajMahal

TajMahal has the ability to steal web session cookies from Internet Explorer, Netscape Navigator, FireFox and RealNetworks applications.

T1539
Steal Web Session Cookie
MalwareRaccoon Stealer

Raccoon Stealer attempts to steal cookies and related information in browser history.

T1539
Steal Web Session Cookie
MalwareXCSSET

XCSSET uses scp to access the ~/Library/Cookies/Cookies.binarycookies file.

T1539
Steal Web Session Cookie
MalwareQakBot

QakBot has the ability to capture web session cookies.

T1539
Steal Web Session Cookie
MalwareCookieMiner

CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine.

T1539
Steal Web Session Cookie
Toolevilginx2

evilginx2 can collect information on each session with a victim including the session cookie.

T1539
Steal Web Session Cookie
MalwareKali365

Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.