Real-world descriptions of how a group, tool or campaign used a technique.
20 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1539 Steal Web Session Cookie |
MalwareTRANSLATEXT | TRANSLATEXT has exfiltrated updated cookies from Google, Naver, Kakao or Daum to the C2 server. |
| T1539 Steal Web Session Cookie |
MalwareLumma Stealer | Lumma Stealer has harvested cookies from various browsers. |
| T1539 Steal Web Session Cookie |
MalwareDarkGate | DarkGate attempts to steal Opera cookies, if present, after terminating the related process. |
| T1539 Steal Web Session Cookie |
MalwareChaes | Chaes has used a script that extracts the web session cookie and sends it to the C2 server. |
| T1539 Steal Web Session Cookie |
MalwareLODEINFO | LODEINFO can list the contents of `%LocalAppData%\Google\Chrome\User Data\` and `%LocalAppData%\Microsoft\Edge\User Data\` to obtain cookies. |
| T1539 Steal Web Session Cookie |
MalwareEVILNUM | EVILNUM can harvest cookies and upload them to the C2 server. |
| T1539 Steal Web Session Cookie |
MalwareGlassWorm | GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers. |
| T1539 Steal Web Session Cookie |
MalwareSpica | Spica has the ability to steal cookies from Chrome, Firefox, Opera, and Edge browsers. |
| T1539 Steal Web Session Cookie |
MalwareBLUELIGHT | BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers. |
| T1539 Steal Web Session Cookie |
MalwareRedLine Stealer | RedLine Stealer has stolen browser cookies and settings. |
| T1539 Steal Web Session Cookie |
MalwareGrandoreiro | Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device. |
| T1539 Steal Web Session Cookie |
MalwareXLoader | XLoader can capture web session cookies and session information from victim browsers. |
| T1539 Steal Web Session Cookie |
MalwareMgBot | MgBot includes modules that can steal cookies from Firefox, Chrome, and Edge web browsers. |
| T1539 Steal Web Session Cookie |
MalwareTajMahal | TajMahal has the ability to steal web session cookies from Internet Explorer, Netscape Navigator, FireFox and RealNetworks applications. |
| T1539 Steal Web Session Cookie |
MalwareRaccoon Stealer | Raccoon Stealer attempts to steal cookies and related information in browser history. |
| T1539 Steal Web Session Cookie |
MalwareXCSSET | XCSSET uses |
| T1539 Steal Web Session Cookie |
MalwareQakBot | QakBot has the ability to capture web session cookies. |
| T1539 Steal Web Session Cookie |
MalwareCookieMiner | CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine. |
| T1539 Steal Web Session Cookie |
Toolevilginx2 | evilginx2 can collect information on each session with a victim including the session cookie. |
| T1539 Steal Web Session Cookie |
MalwareKali365 | Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.