T1539: T1539
Essential information
- MITRE technique ID
T1539- Confidence
- 100/100
- Revoked
- No
- Published
- 08/10/2019 22:04
- Modified
- 27/03/2026 01:08
- Author / Source
- The MITRE Corporation
Aliases
Steal Web Session Cookie
Platforms
windows macos linux Office Suite SaaS
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | credential-access |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (52)
-
The MITRE Corporation Confidence 100
[Star Blizzard](https://attack.mitre.org/groups/G1033) is a cyber espionage and influence group originating in Russia that has been active since at least 2019. [Star Blizzard](https://attack.mitre.org/groups/G1033) campaigns align closely with Russian state…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber…
First seen 01/01/1970 · Last seen 16/11/5138 · -
RastaFarEye usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
MioLab usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Evilnum usesThe MITRE Corporation Confidence 100
[Evilnum](https://attack.mitre.org/groups/G0120) is a financially motivated threat group that has been active since at least 2018.(Citation: ESET EvilNum July 2020)
First seen 01/01/1970 · Last seen 16/11/5138 · -
MRxC0DER usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Thrip](https://attack.mitre.org/groups/G0076) is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Y2K Operators usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Russia usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ToddyCat usesThe MITRE Corporation Confidence 100
[ToddyCat](https://attack.mitre.org/groups/G1022) is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets…
First seen 01/01/1970 · Last seen 16/11/5138 · -
TA4903 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ANTONIO EDUARDO FREDERICO relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (86)
-
JustConvertFiles usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Tsunami usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Invisible Ferret usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ShadowPad - S0596 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Sneaky2FA usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Lokibot - S0447 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Rhadamanthys usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DarkComet - S0334 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PteroVDoor usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Spica usesFamily The MITRE Corporation Confidence 100
[Spica](https://attack.mitre.org/software/S1140) is a custom backdoor written in Rust that has been used by [Star Blizzard](https://attack.mitre.org/groups/G1033) since at least 2023.(Citation: Google TAG COLDRIVER January 2024)
First seen 01/01/1970 · Last seen 16/11/5138 · -
ARTokens usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
RedLine usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (50)
-
AlienVault Confidence 100 10 MITREs 4 Malwares 10 IOCs 4 Observables
-
AlienVault Confidence 100 1 CVE 18 MITREs 1 Malware 14 IOCs 9 Observables
-
AlienVault Confidence 100 24 MITREs 4 Malwares 9 IOCs 9 Observables
-
AlienVault Confidence 100 25 MITREs 6 Malwares 39 IOCs 24 Observables
-
AlienVault Confidence 100 19 MITREs 3 Malwares 4 IOCs 1 APT
-
AlienVault Confidence 100 3 CVEs 21 MITREs 2 Malwares 8 IOCs 2 Observables
-
"Ghost" Code Phishing Analysis relatedAlienVault Confidence 100 20 MITREs 1 Malware
-
AlienVault Confidence 100 20 MITREs 6 Malwares 8 IOCs 5 Observables
-
AlienVault Confidence 100 19 MITREs 1 Malware 21 IOCs 21 Observables
-
AlienVault Confidence 100 21 MITREs 1 Malware 6 IOCs 1 Observable
-
AlienVault Confidence 100 20 MITREs 5 Malwares 8 IOCs 8 Observables
-
AlienVault Confidence 100 19 MITREs 29 IOCs 29 Observables
Vulnerabilities (CVE) (39)
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …
- Attack vector
- LOCAL
- Published
- 22/11/2024
- Modified
- 21/12/2025
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 13/05/2026
- Modified
- 10/06/2026
Citrix NetScaler ADC and NetScaler Gateway contain a buffer overflow vulnerability that allows for sensitive information disclosure when configured as a Gateway …
- Attack vector
- Network
- Published
- 18/10/2023
- Modified
- 21/12/2025
RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim …
- Attack vector
- Network
- Published
- 09/06/2025
- Modified
- 21/12/2025
Type Confusion in V8 in Google Chrome prior to 114.0.5735.198 allowed a remote attacker to potentially exploit heap corruption via a crafted …
- Attack vector
- NETWORK
- Published
- 26/06/2023
- Modified
- 21/12/2025
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows …
- Attack vector
- Network
- Complexity
- Low
- Published
- 20/03/2026
- Modified
- 23/05/2026
Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a denial of service or possibly …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 29/03/2016
- Modified
- 22/04/2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL …
- Attack vector
- NETWORK
- Published
- 02/06/2025
- Modified
- 26/02/2026
Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud contain a deserialization of untrusted data vulnerability involving the …
- Attack vector
- Network
- Published
- 04/09/2025
- Modified
- 21/12/2025
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker …
- Attack vector
- Network
- Published
- 13/02/2026
- Modified
- 20/02/2026
Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML …
- Published
- 03/11/2021
- Modified
- 21/12/2025
WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution
- Published
- 15/02/2022
- Modified
- 02/06/2026
Course Of Action (2)
-
Audit mitigates
-
User Training mitigates
Campaign (1)
-
SolarWinds Compromise uses