FORENSIA

ATT&CK · T1185

Browser Session Hijacking

Tactics: collection

About

Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques. A specific example is when an adversary injects software into a browser that allows them to inherit cookies, HTTP sessions, and SSL client certificates of a user then use the browser as a way to pivot into an authenticated intranet. Executing browser-based behaviors such as pivoting may require specific process permissions, such as <code>SeDebugPrivilege</code> and/or high-integrity/administrator rights. Another example involves pivoting browser traffic from the adversary's browser through the user's browser by setting up a proxy which will redirect web traffic. This does not alter the user's traffic in any way, and the proxy connection can be severed as soon as the browser is closed. The adversary assumes the security context of whichever browser process the proxy is injected into. Browsers typically create a new process for each tab that is opened and permissions and certificates are separated accordingly. With these permissions, an adversary could potentially browse to any resource on an intranet, such as Sharepoint or webmail, that is accessible through the browser and which the browser has sufficient permissions. Browser pivoting may also bypass security provided by 2-factor authentication.

Platforms: WindowsMITRE ATT&CK ↗

Used by actors

1 known groups

Software

14 malware/tools implement this

Cobalt StrikeTrickBotAgent TeslaDridexUrsnifIcedIDCarberpMelcozGrandoreiroChaesQakBotTRANSLATEXTXLoaderevilginx2

Corpus indicators tagged with this technique

403 indicators in the corpus carry T1185.

IndicatorTypeFamilySevSrc
cdec8b20338beb708b5be8d3d7a3041a35a8b0fb92f9186262f312d55ff82066hashsupply_chain801
bb1e6e2650d3d77d732c5eb5176011f914dd87dfhash801
c40126fea6ed24652a3e4e19205075cb02cca3e2hash801
cc4f048e66c5ab3c0f1d767bb8fc464d082641f4888ea3cd14ea3775077c4bf2hash801
524c953e23ff8b768206cf33a529c11ac5510e47cbf6246db79ee671d1231716hash802
b4aa7255af4b016586090a5b451300fahash801
0d681bd160db1b1df5db321a6d2dd9ae81b2609bhash801
bf90fb31e6024d7e6616f5acd0e8aa28738a9095a508c1a986e1e974cb9e79a0hash801
605169623267c4eb73693b22b811dc7ahash801
c984787ccd787629542da68302ed4ceb48fc7e458eab1c15bf45c3070883d26ahash802
134517796178a150a1585672be134169d6877082b598d840baa3f37b0222be26hash801
4fe8bec780537aa223406965415c1f85e83eec1f4e2181cf82e2a7b7516026e6hashphishing801
8e5546c83d764e1287b55cbe868a45344a6f0afa9782d798d03b2b7cfc53ec38hashphishing801
a247a63644c3475f436d076f55523ea39afd8c41hash801
25b6fc4f9c54a28ba7bfc4dfeafb62c99b59ea6f0d17679219b876b321965095sha256phishing801
833008c03d40422192051584d829d730497108bef31751cceb0cc043dd96bbfbsha256phishing801
d6f479736ba55d3c4e895c4940d035cf772f3192fb8dc496f09a801aed16d970sha256phishing801
067ad6221b2224d5cdb64e51c5516132d820cf4d7edf9ec170643943e79c04b7sha256phishing801
f0038a5f46720da5982b6984ceef10cf99359432e102b12a0b0657498d36f670sha256phishing801
8111edf01ac6cb5c77e249d4e84fd92a85b5e89c2e2bef92fbe00b6f1cc2aa8esha256phishing801
f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442hash802
6328567511d88fdc2ae0939c5ef17b7a63d2a833881900de018a4f12f4982525sha256prompt_injection802
9570f77a5e1511869f4e554e7166df9fde081f2583e293c2569621792ed7d9c9hashsupply_chain801
c38954e85bf5433e61e7c8f4230336695624ae88b6953afabf7bf817aa91b638hashsupply_chain801
2c5bc9e95e1e9b73e3ba8870a008802899866a2c0e2e10112aefddf7a96af04ehash801
32da1437a2734224406c7e5e8d756f0c0cd58c0c959478571cbfc0cd564d018ahash801
638b0a77a6d686849a78b500adf5e565hash801
6c3f61d46d4de26b9cb16808bf17c33ae69f651a4b879e7b5612ff7f548e2a82hash801
95fc58dc321b07ecc99d95359bcdee08a5beb519ead8e70e40f33928533a1b14hashphishing803
ec7b0bc82c00464d8e0a59bc19c585e2hashphishing801

Showing the top 30 by severity of 403.