T1539Steal Web Session Cookie
T1539 — Steal Web Session Cookie is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 20 detection use cases covering it and 147 threat-intel articles citing it.
Credential Access
20Use cases
147Articles
0Sub-techniques
1Tactic
Use cases covering this technique (20)
Infostealer — non-browser process accessing browser cookie/login DBs [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Okta Suspicious Use of a Session Cookie [LLM] AmnesiaStealer stream_module: headless Chromium launched with remote-debugging + hardening-off flags [LLM] Evooo1Bot credential sniffer artifact (/tmp/.sniff.log capture file) [LLM] Suspicious ProcessAccess to chrome.exe / msedge.exe with injection-grade rights [LLM] macOS headless Chromium launched with remote-debugging (CDP browser hijack) [LLM] Still Sync Telegram tdata theft via non-Telegram process + SeBackupPrivilege abuse [LLM] AitM session hijack: PaaS phishing-page visit followed by successful Entra sign-in from a different IP [LLM] Endpoint connections to Storm-2945 CaptiveCrunch AiTM doppelganger infrastructure [LLM] Browser-initiated webmail data exfiltration to CL-STA-1114 C2 [LLM] Gitea artifact HMAC signature reused across mismatched task/artifact tuples (CVE-2026-58426) [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro [LLM] Mailcow login with HTML/JS injected into X-Real-IP header (GHSA-jprq-w83q-q62h) [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) [LLM] Discord client tampering via index.js overwrite in discord_desktop_core (Discord Injector)Articles citing this technique (147)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
crit Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner art-38
high Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware art-40
high Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers art-44
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories art-51
crit AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS art-55
high OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning art-69
high DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt art-82
crit A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices art-85
crit Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo art-86
crit Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers art-88
high Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets art-90
crit The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications art-96
crit ESET Threat Report H1 2026 art-312
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-364
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-458
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-468
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-469
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-486
crit Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks art-499
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-515
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-597
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-673
crit ESET Threat Report H2 2025 art-762
crit Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools art-1506
high Preventing XSS in Django art-1837
med You should be using HTTP Strict Transport Security (HSTS) headers in your Node.js server art-1897
crit XSS Attacks: The Next Wave art-3664