Steal Web Session Cookie

T1539

Technique.View on attack.mitre.org

About this technique

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Cookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on disk, in the process memory of the browser, and in network traffic to remote systems. Additionally, other applications on the targets machine might store sensitive authentication cookies in memory (e.g. apps which authenticate to cloud services). Session cookies can be used to bypasses some multi-factor authentication protocols.

There are several examples of malware targeting cookies from web browsers on the local system. Adversaries may also steal cookies by injecting malicious JavaScript content into websites or relying on User Execution by tricking victims into running malicious JavaScript in their browser.

There are also open source frameworks such as `Evilginx2` and `Muraena` that can gather session cookies through a malicious proxy (e.g., Adversary-in-the-Middle) that can be set up by an adversary and used in phishing campaigns.

After an adversary acquires a valid cookie, they can then perform a Web Session Cookie technique to login to the corresponding web application.

Detection rules3

Rules on DetectionCode tagged with T1539.

Sigma2

RuleLevelLog source
SQLite Chromium Profile Data DB Accesshighwindows / process_creation
SQLite Firefox Profile Data DB Accesshighwindows / process_creation

Splunk1

RuleTypeRiskData source
Okta Suspicious Use of a Session CookieAnomalyNULLOkta

Groups8

Software20

Campaigns1

Procedure examples29

Groups8

Used byProcedure example
GroupAPT42

APT42 has used custom malware to steal login and cookie data from common browsers.

GroupEvilnum

Evilnum can steal cookies and session information from browsers.

GroupKimsuky

Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies.

GroupLotus Blossom

Lotus Blossom has used publicly-available tools to steal cookies from browsers such as Chrome.

GroupLuminousMoth

LuminousMoth has used an unnamed post-exploitation tool to steal cookies from the Chrome browser.

GroupSandworm Team

Sandworm Team used information stealer malware to collect browser session cookies.

GroupScattered Spider

Scattered Spider retrieves browser cookies via Raccoon Stealer.

GroupStar Blizzard

Star Blizzard has used EvilGinx to steal the session cookies of victims directed to
phishing domains.

Software20

Used byProcedure example
MalwareBLUELIGHT

BLUELIGHT can harvest cookies from Internet Explorer, Edge, Chrome, and Naver Whale browsers.

MalwareChaes

Chaes has used a script that extracts the web session cookie and sends it to the C2 server.

MalwareCookieMiner

CookieMiner can steal Google Chrome and Apple Safari browser cookies from the victim’s machine.

MalwareDarkGate

DarkGate attempts to steal Opera cookies, if present, after terminating the related process.

Toolevilginx2

evilginx2 can collect information on each session with a victim including the session cookie.

MalwareEVILNUM

EVILNUM can harvest cookies and upload them to the C2 server.

MalwareGlassWorm

GlassWorm has harvested Safari cookies stored within `/Library/Containers/com.apple.Safari/Data/Library/Cookies/ Cookies.binarycookies`. GlassWorm has also stolen cookies within Chromium and Firefox browsers.

MalwareGrandoreiro

Grandoreiro can steal the victim's cookies to use for duplicating the active session from another device.

View all 20 software examples

Campaigns1

Used byProcedure example
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 stole Chrome browser cookies by copying the Chrome profile directories of targeted users.

References7

  1. GitHub Mauraena Open source
    Orrù, M., Trotta, G.. (2019, September 11). Muraena. Retrieved October 14, 2019.
  2. Github evilginx2 Open source
    Gretzky, Kuba. (2019, April 10). Retrieved October 8, 2019.
  3. Kaspersky TajMahal April 2019 Open source
    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.
  4. Krebs Discord Bookmarks 2023 Open source
    Brian Krebs. (2023, May 30). Discord Admins Hacked by Malicious Bookmarks. Retrieved January 2, 2024.
  5. Pass The Cookie Open source
    Rehberger, J. (2018, December). Pivot to the Cloud using Pass the Cookie. Retrieved April 5, 2019.
  6. Talos Roblox Scam 2023 Open source
    Tiago Pereira. (2023, November 2). Attackers use JavaScript URLs, API forms and more to scam users in popular online game “Roblox”. Retrieved January 2, 2024.
  7. Unit 42 Mac Crypto Cookies January 2019 Open source
    Chen, Y., Hu, W., Xu, Z., et. al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved October 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.