FORENSIA

ATT&CK · T1539

Steal Web Session Cookie

Tactics: credential-access

About

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website. Cookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on disk, in the process memory of the browser, and in network traffic to remote systems. Additionally, other applications on the targets machine might store sensitive authentication cookies in memory (e.g. apps which authenticate to cloud services). Session cookies can be used to bypasses some multi-factor authentication protocols. There are several examples of malware targeting cookies from web browsers on the local system. Adversaries may also steal cookies by injecting malicious JavaScript content into websites or relying on User Execution by tricking victims into running malicious JavaScript in their browser. There are also open source frameworks such as `Evilginx2` and `Muraena` that can gather session cookies through a malicious proxy (e.g., Adversary-in-the-Middle) that can be set up by an adversary and used in phishing campaigns. After an adversary acquires a valid cookie, they can then perform a Web Session Cookie technique to login to the corresponding web application.

Platforms: Linux, macOS, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

8 known groups

Software

19 malware/tools implement this

TajMahalCookieMinerGrandoreiroEVILNUMChaesQakBotBLUELIGHTXCSSETDarkGateSpicaMgBotRaccoon StealerTRANSLATEXTXLoaderLumma StealerRedLine Stealerevilginx2GlassWormLODEINFO

Corpus indicators tagged with this technique

5,701 indicators in the corpus carry T1539.

IndicatorTypeFamilySevSrc
65c053030558b4a3588e2590c5c4961a9912180b731686deb3f4c831e765a095hash803
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
f8cbe44fde6914bc8d06426c03c92ed536c891470292e567a586b54af29c2442hash802
1c170b7470d507378ddb78e9d66305f1184e965baaf2d27ededb23a318a58953hash804
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
22b07d2af98bb180474c33d93861124bbdf9b5dd7e42a8bddc654310469a9a2chash803
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801
606966a9ec33765baedf63331595d1168f2a596fhash803
833008c03d40422192051584d829d730497108bef31751cceb0cc043dd96bbfbsha256phishing801
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
808e7154b7af2bc7a4b28d577297c55f77221c355191cbe00f9f1810b6d4a619hashphishing802
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10hashphishing802
25b6fc4f9c54a28ba7bfc4dfeafb62c99b59ea6f0d17679219b876b321965095sha256phishing801
f0038a5f46720da5982b6984ceef10cf99359432e102b12a0b0657498d36f670sha256phishing801
8111edf01ac6cb5c77e249d4e84fd92a85b5e89c2e2bef92fbe00b6f1cc2aa8esha256phishing801
0d681bd160db1b1df5db321a6d2dd9ae81b2609bhash801
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
c099f965144bccd0b590f946659fc3c0747c54aef505b6caaca9078712f455fbsha256801
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
2af0a6135df3502a7f6de4d2de6db73bhash803
ad10ff9043d6f327045943635fcbd0c5918acb79dc998db92ee4c7dee5224710sha256801
64c7dd0a3a3ae49977ac05913d3878000cce14e5d8c1ee05b782bdfd648bde91sha256801
4c9f271242f61f1a31b8146305e9a7ed512c521445d4f7a7a901e301307add3dsha256801
5864a697bd7b339f56b05405f29a097cd027cafdcc4e63c2aaeccccbf930605fsha256801
067ad6221b2224d5cdb64e51c5516132d820cf4d7edf9ec170643943e79c04b7sha256phishing801
d6f479736ba55d3c4e895c4940d035cf772f3192fb8dc496f09a801aed16d970sha256phishing801
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81hashphishing802
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801

Showing the top 30 by severity of 5,701.