Browser Information Discovery

T1217

Technique.View on attack.mitre.org

About this technique

Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.

Browser information may also highlight additional targets after an adversary has access to valid credentials, especially Credentials In Files associated with logins cached by a browser.

Specific storage locations vary based on platform and/or application, but browser information is typically stored in local files and databases (e.g., `%APPDATA%/Google/Chrome`).

Detection rules4

Rules on DetectionCode tagged with T1217.

Sigma4

RuleLevelLog source
Automated Collection Bookmarks Using Get-ChildItem PowerShelllowwindows / ps_script
File And SubFolder Enumeration Via Dir Commandlowwindows / process_creation
Suspicious File Access to Browser Credential Storagelowwindows / file_access
Suspicious Where Executionlowwindows / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups7

Software18

Campaigns4

Procedure examples29

Groups7

Used byProcedure example
GroupAPT38

APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources.

GroupChimera

Chimera has used type \\<hostname>\c$\Users\<username>\Favorites\Links\Bookmarks bar\Imported From IE\*citrix* for bookmark discovery.

GroupFox Kitten

Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets.

GroupKimsuky

Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys.

GroupMoonstone Sleet

Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information.

GroupScattered Spider

Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer.

GroupVolt Typhoon

Volt Typhoon has targeted the browsing history of network administrators.

Software18

Used byProcedure example
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets.

MalwareCalisto

Calisto collects information on bookmarks from Google Chrome.

MalwareCuckoo Stealer

Cuckoo Stealer can collect bookmarks, cookies, and history from Safari.

MalwareDarkWatchman

DarkWatchman can retrieve browser history.

MalwareDtrack

Dtrack can retrieve browser history.

ToolEmpire

Empire has the ability to gather browser data such as bookmarks and visited sites.

MalwareGlassWorm

GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets.

MalwareLightSpy

To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist` file. It also utilizes Apple's `CWWiFiClient` API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values.

View all 18 software examples

Campaigns4

Used byProcedure example
Campaign3CX Supply Chain Attack

During the 3CX Supply Chain Attack, AppleJeus leveraged ICONICSTEALER to steal browser information to include browser history located on the infected host.

CampaignJuicy Mix

During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information.

CampaignOuter Space

During Outer Space, OilRig used a Chrome data dumper named MKG.

References2

  1. Chrome Roaming Profiles Open source
    Chrome Enterprise and Education Help. (n.d.). Use Chrome Browser with Roaming User Profiles. Retrieved March 28, 2023.
  2. Kaspersky Autofill Open source
    Golubev, S. (n.d.). How malware steals autofill data from browsers. Retrieved March 28, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.