LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1539: Steal Web Session Cookie

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Cookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on disk, in the process memory of the browser, and in network traffic to remote systems. Additionally, other applications on the targets machine might store sensitive authentication cookies in memory (e.g. apps which authenticate to cloud services). Session cookies can be used to bypasses some multi-factor authentication protocols.[1]

There are several examples of malware targeting cookies from web browsers on the local system.[2][3] Adversaries may also steal cookies by injecting malicious JavaScript content into websites or relying on User Execution by tricking victims into running malicious JavaScript in their browser.[4][5]

There are also open source frameworks such as `Evilginx2` and `Muraena` that can gather session cookies through a malicious proxy (e.g., Adversary-in-the-Middle) that can be set up by an adversary and used in phishing campaigns.[6][7]

After an adversary acquires a valid cookie, they can then perform a Web Session Cookie technique to login to the corresponding web application.

EnterpriseT1539TechniqueObject v1.5Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Stealing web session cookies matters because it can let an adversary access SaaS, office suite, and web applications as an already-authenticated user without knowing the password. This is especially important for executives and security leaders because cookies may remain valid for extended periods and can sometimes undermine the expected protection value of multi-factor authentication. The practical risk is not just credential theft; it is authenticated access to business services, cloud workflows, and sensitive applications using an existing user session.

Executive priority

Prioritize this technique where business-critical services depend on browser or app-based sessions across Windows, macOS, Linux, SaaS, and Office Suite environments. Leaders should ask whether the organization can prove it collects the evidence needed to investigate cookie theft from endpoints, browsers, memory, and network paths, and whether incident response playbooks include session revocation, account review, and re-authentication decisions. This technique also affects audit and compliance readiness because MFA alone may not be sufficient evidence of access control resilience if stolen sessions are not monitored or invalidated.

Technical view

ATT&CK places T1539 under Credential Access. The supplied object describes cookies being stolen from disk, browser process memory, network traffic, and other applications that authenticate to cloud services. It also notes paths involving malicious JavaScript, user execution, and malicious proxy activity associated with adversary-in-the-middle phishing frameworks. SOC and IR teams should validate coverage against endpoint file access to browser cookie stores, suspicious access to browser or application memory, anomalous web authentication/session reuse, and network indicators consistent with session interception. Because MITRE does not provide official detection text for this object, detection engineering should align with the related DET0509 strategy and test visibility across file, memory, and network artifacts.

Likely telemetry

  • Endpoint file access telemetry for browser profile directories and cookie stores
  • Process and memory access telemetry involving browsers and applications that authenticate to web or cloud services
  • Browser, script, and web activity logs where available, especially suspicious JavaScript or user-driven browser actions
  • Network traffic and proxy logs that may show unusual web session handling or access through suspicious intermediaries
  • SaaS and Office Suite authentication, session, and audit logs showing session use, location changes, device changes, or abnormal access patterns

Detection direction

  • Confirm whether DET0509-style coverage exists for file, memory, and network artifacts rather than relying only on failed login or password-based alerts.
  • Tune detections for suspicious access to browser cookie storage and browser process memory, while accounting for legitimate browser, backup, endpoint security, and administrative activity.
  • Correlate endpoint evidence with SaaS or Office Suite session activity, because the value of the stolen cookie is realized when it is reused against a web application or service.
  • Look for context from related techniques named in the object, including User Execution, Adversary-in-the-Middle, and Web Session Cookie use, without assuming they are always present.
  • Treat MFA success as insufficient by itself; the supplied description states stolen session cookies may bypass some MFA protocols.

Mitigation priorities

  • Start with auditing: ensure endpoint, browser-relevant, network, SaaS, and Office Suite logs are enabled and reviewable for investigation and compliance evidence.
  • Apply software configuration controls that reduce exposure of sensitive session material where supported by the relevant applications and services.
  • Use multi-factor authentication for critical services, while recognizing from the ATT&CK description that stolen session cookies may bypass some MFA protocols.
  • Restrict web-based content through policies such as URL filtering, download restrictions, script control, and browser behavior controls to reduce exposure to malicious JavaScript, unsafe sites, and phishing infrastructure.
  • Maintain software updates across operating systems, browsers, applications, and related components to reduce opportunities for malware or web-based compromise paths.
Additional notes and limits

The relationship context shows use by multiple ATT&CK groups, a campaign, and several malware families across Windows and macOS examples, plus enterprise platforms that include Linux, macOS, Office Suite, SaaS, and Windows. This supports treating session-cookie theft as a cross-platform identity and cloud-access risk rather than a narrow endpoint issue. The defensive decision point is whether teams can connect endpoint acquisition evidence to authenticated web-session use and then revoke or contain affected sessions quickly.

Official MITRE detection text is not provided for T1539 in the supplied object. The guidance above is therefore derived from the official description, platforms, tactic, external references, DET0509 relationship, and listed mitigations. Local validation is required to determine which browsers, SaaS services, audit logs, endpoint controls, and session-management capabilities are actually present in a given environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Steal Web Session Cookie

An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.

Cookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on disk, in the process memory of the browser, and in network traffic to remote systems. Additionally, other applications on the targets machine might store sensitive authentication cookies in memory (e.g. apps which authenticate to cloud services). Session cookies can be used to bypasses some multi-factor authentication protocols.[1]

There are several examples of malware targeting cookies from web browsers on the local system.[2][3] Adversaries may also steal cookies by injecting malicious JavaScript content into websites or relying on User Execution by tricking victims into running malicious JavaScript in their browser.[4][5]

There are also open source frameworks such as `Evilginx2` and `Muraena` that can gather session cookies through a malicious proxy (e.g., Adversary-in-the-Middle) that can be set up by an adversary and used in phishing campaigns.[6][7]

After an adversary acquires a valid cookie, they can then perform a Web Session Cookie technique to login to the corresponding web application.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1014: LuminousMoth

LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanmar, the Philippines, Thailand, and other parts of Southeast Asia. Some security researchers have concluded there is a connection between LuminousMoth and Mustang Panda based on similar targeting and TTPs, as well as network infrastructure overlaps.[1][2]

GroupEnterprise

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

GroupEnterprise

G1015: Scattered Spider

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. [1] [2] The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. [2] Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. [3] [4] [5] Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365. [6]

GroupEnterprise

G1033: Star Blizzard

Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have included persistent phishing and credential theft against academic, defense, government, NGO, and think tank organizations in NATO countries, particularly the US and the UK.[1][2][3][4]

GroupEnterprise

G1044: APT42

APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance.[1] The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries and countries since at least 2015.[1] APT42 starts cyber operations through spearphishing emails and/or the PINEFLOWER Android malware, then monitors and collects information from the compromised systems and devices.[1] Finally, APT42 exfiltrates data using native features and open-source tools.[2]

APT42 activities have been linked to Magic Hound by other commercial vendors. While there are behavior and software overlaps between Magic Hound and APT42, they appear to be distinct entities and are tracked as separate entities by their originating vendor.

MalwareEnterprise

S0531: Grandoreiro

Grandoreiro is a banking trojan written in Delphi that was first observed in 2016 and uses a Malware-as-a-Service (MaaS) business model. Grandoreiro has confirmed victims in Brazil, Mexico, Portugal, and Spain.[1][2]

Windows
MalwareEnterprise

S1207: XLoader

XLoader is an infostealer malware in use since at least 2016. Previously known and sometimes still referred to as Formbook, XLoader is a Malware as a Service (MaaS) known for stealing data from web browsers, email clients and File Transfer Protocol (FTP) applications.[1][2][3][4][5]

Windows
MalwareEnterprise

S9010: GlassWorm

GlassWorm is a worm that propagated through supply chain attacks by compromising repository credentials from victim environments and having malicious payloads added to those compromised accounts for distribution to victims across the various development ecosystems.[1][2][3] GlassWorm has numerous variants, including Rust binaries, encrypted JavaScript and a variant leveraging invisible Unicode characters that made reverse engineering difficult.[4][1][5] GlassWorm has employed a unique command and control (C2) methodology using Solana blockchain.[6][1] GlassWorm was first reported in October 2025.[6][1][3]

macOSWindows
MalwareEnterprise

S0492: CookieMiner

CookieMiner is mac-based malware that targets information associated with cryptocurrency exchanges as well as enabling cryptocurrency mining on the victim system itself. It was first discovered in the wild in 2019.[1]

macOS
ToolEnterprise

S9003: evilginx2

evilginx2 is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. evilginx2 can be used as a reverse proxy between victims and legitimate web services to intercept and capture credentials, authentication tokens, and session cookies.[1][2][3]

IaaSIdentity ProviderOffice Suite
MalwareEnterprise

S0650: QakBot

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware, most notably ProLock and Egregor.[1][2][3][4]

Windows
MalwareEnterprise

S1201: TRANSLATEXT

TRANSLATEXT is malware that is believed to be used by Kimsuky.[1] TRANSLATEXT masqueraded as a Google Translate extension for Google Chrome, but is actually a collection of four malicious Javascript files that perform defense evasion, information collection and exfiltration.[1]

Windows
MalwareEnterprise

S0631: Chaes

Chaes is a multistage information stealer written in several programming languages that collects login credentials, credit card numbers, and other financial information. Chaes was first observed in 2020, and appears to primarily target victims in Brazil as well as other e-commerce customers in Latin America.[1]

Windows
MalwareEnterprise

S1240: RedLine Stealer

RedLine Stealer is an information-stealer malware variant first identified in 2020.[1][2][3] RedLine Stealer is a Malware as a Service (MaaS) and was reportedly sold as either a one-time purchase or a monthly subscription service.[1][4] Information obtained from RedLine Stealer has been known to be sold on the deep and dark web to Initial Access Brokers (IABs), who use or resell the stolen credentials for further intrusions.[5][4]

Windows
CampaignEnterprise

C0024: SolarWinds Compromise

The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject malicious code into the SolarWinds Orion software build process that was later distributed through a normal software update; they also used password spraying, token theft, API abuse, spear phishing, and other supply chain attacks to compromise user accounts and leverage their associated access. Victims of this campaign included government, consulting, technology, telecom, and other organizations in North America, Europe, Asia, and the Middle East. This activity has been labled the StellarParticle campaign in industry reporting.[1] Industry reporting also initially referred to the actors involved in this campaign as UNC2452, NOBELIUM, Dark Halo, and SolarStorm.[2][3][4][5][1][6][7][8]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to Russia's Foreign Intelligence Service (SVR); public statements included citations to APT29, Cozy Bear, and The Dukes.[9][10][11] The US government assessed that of the approximately 18,000 affected public and private sector customers of Solar Winds’ Orion product, a much smaller number were compromised by follow-on APT29 activity on their systems.[12]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.5
Created
Modified
Raw hash
46590843583f53de...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.5Current bundle46590843583f…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Pass The Cookie

    Rehberger, J. (2018, December). Pivot to the Cloud using Pass the Cookie. Retrieved April 5, 2019.

    Open source URL
  2. [2]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  3. [3]
    Unit 42 Mac Crypto Cookies January 2019

    Chen, Y., Hu, W., Xu, Z., et. al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved October 14, 2019.

    Open source URL
  4. [4]
    Talos Roblox Scam 2023

    Tiago Pereira. (2023, November 2). Attackers use JavaScript URLs, API forms and more to scam users in popular online game “Roblox”. Retrieved January 2, 2024.

    Open source URL
  5. [5]
    Krebs Discord Bookmarks 2023

    Brian Krebs. (2023, May 30). Discord Admins Hacked by Malicious Bookmarks. Retrieved January 2, 2024.

    Open source URL
  6. [6]
    Github evilginx2

    Gretzky, Kuba. (2019, April 10). Retrieved October 8, 2019.

    Open source URL
  7. [7]
    GitHub Mauraena

    Orrù, M., Trotta, G.. (2019, September 11). Muraena. Retrieved October 14, 2019.

    Open source URL
  8. [8]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  9. [9]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  10. [10]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  11. [11]
    Leonard TAG 2023

    Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024.

    Open source URL
  12. [12]
    IBM Grandoreiro April 2020

    Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

    Open source URL
  13. [13]
    Token tactics

    Microsoft Incident Response. (2022, November 16). Token tactics: How to prevent, detect, and respond to cloud token theft. Retrieved December 26, 2023.

    Open source URL
  14. [14]
    Session Management Cheat Sheet

    OWASP CheatSheets Series Team. (n.d.). Session Management Cheat Sheet. Retrieved December 26, 2023.

    Open source URL
  15. [15]
    Google XLoader 2017

    Nart Villeneuve, Randi Eitzman, Sandor Nemes & Tyler Dean, Google Cloud. (2017, October 5). Significant FormBook Distribution Campaigns Impacting the U.S. and South Korea. Retrieved March 11, 2025.

    Open source URL
  16. [16]
    CISA Scattered Spider Advisory November 2023

    CISA. (2023, November 16). Cybersecurity Advisory: Scattered Spider (AA23-320A). Retrieved March 18, 2024.

    Open source URL
  17. [17]
    ESET EvilNum July 2020

    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

    Open source URL
  18. [18]
    Socket GlassWorm January 2026

    Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.

    Open source URL
  19. [19]
    Koi Glassworm New Tricks December 2025

    Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026.

    Open source URL
  20. [20]
    Unit42 CookieMiner Jan 2019

    Chen, y., et al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved July 22, 2020.

    Open source URL
  21. [21]
    Evilginx 2 July 2018

    Gretzky, K.. (2018, July 26). Evilginx 2 - Next Generation of Phishing 2FA Tokens. Retrieved October 14, 2019.

    Open source URL
  22. [22]
    Sophos Evilginx MAR 2025

    Everts, M. (2025, March 28). Stealing user credentials with evilginx. Retrieved January 27, 2026.

    Open source URL
  23. [23]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  24. [24]
    Cisco LotusBlossom 2025

    Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.

    Open source URL
  25. [25]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  26. [26]
    Kroll Qakbot June 2020

    Sette, N. et al. (2020, June 4). Qakbot Malware Now Exfiltrating Emails for Sophisticated Thread Hijacking Attacks. Retrieved September 27, 2021.

    Open source URL
  27. [27]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  28. [28]
    Prevailion EvilNum May 2020

    Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024.

    Open source URL
  29. [29]
    Cybereason Chaes Nov 2020

    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

    Open source URL
  30. [30]
    Volexity InkySquid BLUELIGHT August 2021

    Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.

    Open source URL
  31. [31]
    CrowdStrike StellarParticle January 2022

    CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.

    Open source URL
  32. [32]
    ESET RedLine Stealer November 2024

    Alexandre Cote Cyr. (2024, November 8). Life on a crooked RedLine: Analyzing the infamous infostealer’s backend. Retrieved September 17, 2025.

    Open source URL
  33. [33]
    Kroll RedLine Stealer August 2024

    George Glass. (2024, August 14). REDLINESTEALER Malware Driving the Initial Access Broker Market. Retrieved September 17, 2025.

    Open source URL
  34. [34]
    Proofpoint RedLine Stealer March 2020

    Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025.

    Open source URL
  35. [35]
    Splunk RedLine Stealer June 2023

    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

    Open source URL
  36. [36]
    ESET EvasivePanda 2023

    Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.

    Open source URL
  37. [37]
    trendmicro xcsset xcode project 2020

    Mac Threat Response, Mobile Research Team. (2020, August 13). The XCSSET Malware: Inserts Malicious Code Into Xcode Projects, Performs UXSS Backdoor Planting in Safari, and Leverages Two Zero-day Exploits. Retrieved October 5, 2021.

    Open source URL
  38. [38]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  39. [39]
    Sekoia Raccoon2 2022

    Pierre Le Bourhis, Quentin Bourgue, & Sekoia TDR. (2022, June 29). Raccoon Stealer v2 - Part 2: In-depth analysis. Retrieved August 1, 2024.

    Open source URL
  40. [40]
    Cybereason LumaStealer Undated

    Cybereaon Security Services Team. (n.d.). Your Data Is Under New Lummanagement: The Rise of LummaStealer. Retrieved March 22, 2025.

    Open source URL
  41. [41]
    Fortinet LummaStealer 2024

    Cara Lin, Fortinet. (2024, January 8). Deceptive Cracked Software Spreads Lumma Variant on YouTube. Retrieved March 22, 2025.

    Open source URL
  42. [42]
    TrendMicro LummaStealer 2025

    Buddy Tancio, Fe Cureg, and Jovit Samaniego, Trend Micro. (2025, January 30). Lumma Stealer’s GitHub-Based Delivery Explored via Managed Detection and Response. Retrieved March 22, 2025.

    Open source URL
  43. [43]
    Mandiant APT42-charms

    Mandiant. (n.d.). APT42: Crooked Charms, Cons and Compromises. Retrieved October 9, 2024.

    Open source URL
  44. [44]
    ESET MirrorFace DEC 2022

    Breitenbacher, D. (2022, December 14). Unmasking MirrorFace: Operation LiberalFace targeting Japanese political entities. Retrieved April 17, 2026.

    Open source URL
  45. [45]
    GitHub Mauraena

    Orrù, M., Trotta, G.. (2019, September 11). Muraena. Retrieved October 14, 2019.

    Open source URL
  46. [46]
    GitHub Mauraena

    Orrù, M., Trotta, G.. (2019, September 11). Muraena. Retrieved October 14, 2019.

    Open source URL
  47. [47]
    Github evilginx2

    Gretzky, Kuba. (2019, April 10). Retrieved October 8, 2019.

    Open source URL
  48. [48]
    Github evilginx2

    Gretzky, Kuba. (2019, April 10). Retrieved October 8, 2019.

    Open source URL
  49. [49]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  50. [50]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  51. [51]
    Krebs Discord Bookmarks 2023

    Brian Krebs. (2023, May 30). Discord Admins Hacked by Malicious Bookmarks. Retrieved January 2, 2024.

    Open source URL
  52. [52]
    Krebs Discord Bookmarks 2023

    Brian Krebs. (2023, May 30). Discord Admins Hacked by Malicious Bookmarks. Retrieved January 2, 2024.

    Open source URL
  53. [53]
    Pass The Cookie

    Rehberger, J. (2018, December). Pivot to the Cloud using Pass the Cookie. Retrieved April 5, 2019.

    Open source URL
  54. [54]
    Pass The Cookie

    Rehberger, J. (2018, December). Pivot to the Cloud using Pass the Cookie. Retrieved April 5, 2019.

    Open source URL
  55. [55]
    Talos Roblox Scam 2023

    Tiago Pereira. (2023, November 2). Attackers use JavaScript URLs, API forms and more to scam users in popular online game “Roblox”. Retrieved January 2, 2024.

    Open source URL
  56. [56]
    Talos Roblox Scam 2023

    Tiago Pereira. (2023, November 2). Attackers use JavaScript URLs, API forms and more to scam users in popular online game “Roblox”. Retrieved January 2, 2024.

    Open source URL
  57. [57]
    Unit 42 Mac Crypto Cookies January 2019

    Chen, Y., Hu, W., Xu, Z., et. al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved October 14, 2019.

    Open source URL
  58. [58]
    Unit 42 Mac Crypto Cookies January 2019

    Chen, Y., Hu, W., Xu, Z., et. al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved October 14, 2019.

    Open source URL
  59. [59]
    mitre-attackT1539
    Open source URL
  60. [60]
    mitre-attackT1539
    Open source URL
  61. [61]
    mitre-attackT1539
    Open source URL
  62. [62]
    Kaspersky LuminousMoth July 2021

    Lechtik, M, and etl. (2021, July 14). LuminousMoth APT: Sweeping attacks for the chosen few. Retrieved October 20, 2022.

    Open source URL
  63. [63]
    S2W Troll Stealer 2024

    Jiho Kim & Sebin Lee, S2W. (2024, February 7). Kimsuky disguised as a Korean company signed with a valid certificate to distribute Troll Stealer (English ver.). Retrieved January 17, 2025.

    Open source URL
  64. [64]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  65. [65]
    Leonard TAG 2023

    Billy Leonard. (2023, April 19). Ukraine remains Russia’s biggest cyber focus in 2023. Retrieved March 1, 2024.

    Open source URL
  66. [66]
    IBM Grandoreiro April 2020

    Abramov, D. (2020, April 13). Grandoreiro Malware Now Targeting Banks in Spain. Retrieved November 12, 2020.

    Open source URL
  67. [67]
    Session Management Cheat Sheet

    OWASP CheatSheets Series Team. (n.d.). Session Management Cheat Sheet. Retrieved December 26, 2023.

    Open source URL
  68. [68]
    Token tactics

    Microsoft Incident Response. (2022, November 16). Token tactics: How to prevent, detect, and respond to cloud token theft. Retrieved December 26, 2023.

    Open source URL
  69. [69]
    Google XLoader 2017

    Nart Villeneuve, Randi Eitzman, Sandor Nemes & Tyler Dean, Google Cloud. (2017, October 5). Significant FormBook Distribution Campaigns Impacting the U.S. and South Korea. Retrieved March 11, 2025.

    Open source URL
  70. [70]
    CISA Scattered Spider Advisory November 2023

    CISA. (2023, November 16). Cybersecurity Advisory: Scattered Spider (AA23-320A). Retrieved March 18, 2024.

    Open source URL
  71. [71]
    ESET EvilNum July 2020

    Porolli, M. (2020, July 9). More evil: A deep look at Evilnum and its toolset. Retrieved January 22, 2021.

    Open source URL
  72. [72]
    Koi Glassworm New Tricks December 2025

    Gal Hachamov. (2025, December 29). GlassWorm Goes Mac: Fresh Infrastructure, New Tricks. Retrieved April 10, 2026.

    Open source URL
  73. [73]
    Socket GlassWorm January 2026

    Kirill Boychenko. (2026, January 31). GlassWorm Loader Hits Open VSX via Developer Account Compromise. Retrieved April 10, 2026.

    Open source URL
  74. [74]
    Unit42 CookieMiner Jan 2019

    Chen, y., et al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved July 22, 2020.

    Open source URL
  75. [75]
    Evilginx 2 July 2018

    Gretzky, K.. (2018, July 26). Evilginx 2 - Next Generation of Phishing 2FA Tokens. Retrieved October 14, 2019.

    Open source URL
  76. [76]
    Sophos Evilginx MAR 2025

    Everts, M. (2025, March 28). Stealing user credentials with evilginx. Retrieved January 27, 2026.

    Open source URL
  77. [77]
    CISA Star Blizzard Advisory December 2023

    CISA, et al. (2023, December 7). Russian FSB Cyber Actor Star Blizzard Continues Worldwide Spear-phishing Campaigns. Retrieved June 13, 2024.

    Open source URL
  78. [78]
    Cisco LotusBlossom 2025

    Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.

    Open source URL
  79. [79]
    Google TAG COLDRIVER January 2024

    Shields, W. (2024, January 18). Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware. Retrieved June 13, 2024.

    Open source URL
  80. [80]
    Kaspersky QakBot September 2021

    Kuzmenko, A. et al. (2021, September 2). QakBot technical analysis. Retrieved September 27, 2021.

    Open source URL
  81. [81]
    Kroll Qakbot June 2020

    Sette, N. et al. (2020, June 4). Qakbot Malware Now Exfiltrating Emails for Sophisticated Thread Hijacking Attacks. Retrieved September 27, 2021.

    Open source URL
  82. [82]
    Prevailion EvilNum May 2020

    Adamitis, D. (2020, May 6). Phantom in the Command Shell. Retrieved November 17, 2024.

    Open source URL
  83. [83]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  84. [84]
    Zscaler Kimsuky TRANSLATEXT

    Park, S. (2024, June 27). Kimsuky deploys TRANSLATEXT to target South Korean academia. Retrieved October 14, 2024.

    Open source URL
  85. [85]
    Cybereason Chaes Nov 2020

    Salem, E. (2020, November 17). CHAES: Novel Malware Targeting Latin American E-Commerce. Retrieved June 30, 2021.

    Open source URL
  86. [86]
    Volexity InkySquid BLUELIGHT August 2021

    Cash, D., Grunzweig, J., Meltzer, M., Adair, S., Lancaster, T. (2021, August 17). North Korean APT InkySquid Infects Victims Using Browser Exploits. Retrieved September 30, 2021.

    Open source URL
  87. [87]
    CrowdStrike StellarParticle January 2022

    CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.

    Open source URL
  88. [88]
    ESET RedLine Stealer November 2024

    Alexandre Cote Cyr. (2024, November 8). Life on a crooked RedLine: Analyzing the infamous infostealer’s backend. Retrieved September 17, 2025.

    Open source URL
  89. [89]
    Kroll RedLine Stealer August 2024

    George Glass. (2024, August 14). REDLINESTEALER Malware Driving the Initial Access Broker Market. Retrieved September 17, 2025.

    Open source URL
  90. [90]
    Proofpoint RedLine Stealer March 2020

    Proofpoint Threat Insight Team, Jeremy H, Axel F. (2020, March 16). New Redline Password Stealer Malware. Retrieved September 17, 2025.

    Open source URL
  91. [91]
    Splunk RedLine Stealer June 2023

    Splunk Threat Research Team. (2023, June 1). Do Not Cross The 'RedLine' Stealer: Detections and Analysis. Retrieved September 17, 2025.

    Open source URL
  92. [92]
    ESET EvasivePanda 2023

    Facundo Muñoz. (2023, April 26). Evasive Panda APT group delivers malware via updates for popular Chinese software. Retrieved July 25, 2024.

    Open source URL
  93. [93]
    trendmicro xcsset xcode project 2020

    Mac Threat Response, Mobile Research Team. (2020, August 13). The XCSSET Malware: Inserts Malicious Code Into Xcode Projects, Performs UXSS Backdoor Planting in Safari, and Leverages Two Zero-day Exploits. Retrieved October 5, 2021.

    Open source URL
  94. [94]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  95. [95]
    Kaspersky TajMahal April 2019

    GReAT. (2019, April 10). Project TajMahal – a sophisticated new APT framework. Retrieved October 14, 2019.

    Open source URL
  96. [96]
    Rapid7 BlackBasta 2024

    McGraw, T. (2024, December 4). Black Basta Ransomware Campaign Drops Zbot, DarkGate, and Custom Malware. Retrieved December 9, 2024.

    Open source URL
  97. [97]
    Sekoia Raccoon2 2022

    Pierre Le Bourhis, Quentin Bourgue, & Sekoia TDR. (2022, June 29). Raccoon Stealer v2 - Part 2: In-depth analysis. Retrieved August 1, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.