Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1539

T1539Steal Web Session Cookie

T1539 — Steal Web Session Cookie is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 20 detection use cases covering it and 147 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
20Use cases
147Articles
0Sub-techniques
1Tactic

Use cases covering this technique (20)

Infostealer — non-browser process accessing browser cookie/login DBs Internal actions · alerting DSΣP [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD Okta Suspicious Use of a Session Cookie ESCU actions · hunting P [LLM] AmnesiaStealer stream_module: headless Chromium launched with remote-debugging + hardening-off flags Bespoke actions · alerting DSΣPCS [LLM] Evooo1Bot credential sniffer artifact (/tmp/.sniff.log capture file) Bespoke actions · alerting DSΣPCS [LLM] Suspicious ProcessAccess to chrome.exe / msedge.exe with injection-grade rights Bespoke actions · alerting DSΣPDD [LLM] macOS headless Chromium launched with remote-debugging (CDP browser hijack) Bespoke actions · alerting DSΣPCS [LLM] Still Sync Telegram tdata theft via non-Telegram process + SeBackupPrivilege abuse Bespoke actions · hunting DSΣPDDCS [LLM] AitM session hijack: PaaS phishing-page visit followed by successful Entra sign-in from a different IP Bespoke actions · alerting DS [LLM] Endpoint connections to Storm-2945 CaptiveCrunch AiTM doppelganger infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] Browser-initiated webmail data exfiltration to CL-STA-1114 C2 Bespoke actions · hunting DSΣPDDCS [LLM] Gitea artifact HMAC signature reused across mismatched task/artifact tuples (CVE-2026-58426) Bespoke exploit · alerting SP [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro Bespoke c2 · alerting DSΣPDDCS [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) Bespoke actions · hunting DSPDDCS [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro Bespoke c2 · hunting DSΣPDDCS [LLM] Mailcow login with HTML/JS injected into X-Real-IP header (GHSA-jprq-w83q-q62h) Bespoke delivery · alerting SPDD [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) Bespoke install · hunting DSΣPCS [LLM] Discord client tampering via index.js overwrite in discord_desktop_core (Discord Injector) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (147)