T1539Steal Web Session Cookie
T1539 — Steal Web Session Cookie is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 16 detection use cases covering it and 115 threat-intel articles citing it.
Credential Access
16Use cases
115Articles
0Sub-techniques
1Tactic
Use cases covering this technique (16)
Infostealer — non-browser process accessing browser cookie/login DBs [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes [WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Okta Suspicious Use of a Session Cookie [LLM] WScript enumerating browser profiles for Telegram session and wallet extensions [LLM] ChromEggscalator: Chromium launched with --remote-debugging-port for cookie/credential theft [LLM] Browser-initiated webmail data exfiltration to CL-STA-1114 C2 [LLM] Cyberhaven trojanized Chrome extension C2 callback to cyberhavenext.pro [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) [LLM] Cyberhaven compromised extension C2 beacon to cyberhavenext[.]pro [LLM] Mailcow login with HTML/JS injected into X-Real-IP header (GHSA-jprq-w83q-q62h) [LLM] Hoppscotch device-login open redirect token theft via localhost.* / sslip.io bypass [LLM] Non-browser process copying Chrome/Edge/Brave Login Data, Web Data, or wallet extension LevelDB state [LLM] PTX-Player macOS infostealer artifacts (SHA256 + dropped /private/tmp logs) [LLM] Discord client tampering via index.js overwrite in discord_desktop_core (Discord Injector)Articles citing this technique (115)
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-74
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-97
crit ESET Threat Report H1 2026 art-221
crit 400+ AUR Packages Hijacked: What the “Atomic Arch” Campaign Means for Supply-Chain Security art-316
high GitHub breached via a malicious VS Code extension: why developer devices are the real target art-412
high The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised art-422
high Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again! art-423
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440
crit Security metamorphosis: a Mythos-ready architecture checklist for autonomous AI attacks art-454
high "A Mini Shai-Hulud Has Appeared": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages art-471
crit ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push art-556
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
crit Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools art-1483
high Preventing XSS in Django art-1814
med You should be using HTTP Strict Transport Security (HSTS) headers in your Node.js server art-1874
crit XSS Attacks: The Next Wave art-3641