Browser Session Hijacking

T1185

Technique.View on attack.mitre.org

About this technique

Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.

A specific example is when an adversary injects software into a browser that allows them to inherit cookies, HTTP sessions, and SSL client certificates of a user then use the browser as a way to pivot into an authenticated intranet. Executing browser-based behaviors such as pivoting may require specific process permissions, such as SeDebugPrivilege and/or high-integrity/administrator rights.

Another example involves pivoting browser traffic from the adversary's browser through the user's browser by setting up a proxy which will redirect web traffic. This does not alter the user's traffic in any way, and the proxy connection can be severed as soon as the browser is closed. The adversary assumes the security context of whichever browser process the proxy is injected into. Browsers typically create a new process for each tab that is opened and permissions and certificates are separated accordingly. With these permissions, an adversary could potentially browse to any resource on an intranet, such as Sharepoint or webmail, that is accessible through the browser and which the browser has sufficient permissions. Browser pivoting may also bypass security provided by 2-factor authentication.

Detection rules11

Rules on DetectionCode tagged with T1185.

Sigma2

RuleLevelLog source
Potential Data Stealing Via Chromium Headless Debugginghighwindows / process_creation
Browser Started with Remote Debuggingmediumwindows / process_creation

Splunk9

RuleTypeRiskData source
ASL AWS Concurrent Sessions From Different IpsAnomalyNULLASL AWS CloudTrail
AWS Concurrent Sessions From Different IpsTTPNULLAWS CloudTrail DescribeEventAggregates
Azure AD Concurrent Sessions From Different IpsTTPNULLAzure Active Directory
O365 Concurrent Sessions From Different IpsTTPNULLO365 UserLoggedIn
Windows Browser Process Launched with Unusual FlagsAnomalyNULLSysmon EventID 1
Windows Chrome Auto-Update Disabled via RegistryAnomalyNULLSysmon EventID 13
Windows Chrome Enable Extension Loading via Command-LineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Chrome Extension Allowed Registry ModificationAnomalyNULLSysmon EventID 13
Windows Chromium Process Loaded Extension via Command-LineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups1

Software15

Campaigns0

None recorded.

Procedure examples16

Groups1

Used byProcedure example
GroupKimsuky

Kimsuky has the ability to use form-grabbing to extract emails and passwords from web data forms.

Software15

Used byProcedure example
MalwareAgent Tesla

Agent Tesla has the ability to use form-grabbing to extract data from web data forms.

MalwareCarberp

Carberp has captured credentials when a user performs login through a SSL session.

MalwareChaes

Chaes has used the Puppeteer module to hook and monitor the Chrome web browser to collect user information from infected hosts.

MalwareCobalt Strike

Cobalt Strike can perform browser pivoting and inject into a user's browser to inherit cookies, authenticated HTTP sessions, and client SSL certificates.

MalwareDridex

Dridex can perform browser attacks via web injects to steal information such as credentials, certificates, and cookies.

Toolevilginx2

evilginx2 can inject custom POST arguments into requests to silently enable "Remember Me" options during authentication to stay logged in across browser sessions.

MalwareGrandoreiro

Grandoreiro can monitor browser activity for online banking actions and display full-screen overlay images to block user access to the intended site or present additional data fields.

MalwareIcedID

IcedID has used web injection attacks to redirect victims to spoofed sites designed to harvest banking and other credentials. IcedID can use a self signed TLS certificate in connection with the spoofed site and simultaneously maintains a live connection with the legitimate site to display the correct URL and certificates in the browser.

View all 15 software examples

References4

  1. Cobalt Strike Browser Pivot Open source
    Mudge, R. (n.d.). Browser Pivoting. Retrieved January 10, 2018.
  2. ICEBRG Chrome Extensions Open source
    De Tore, M., Warner, J. (2018, January 15). MALICIOUS CHROME EXTENSIONS ENABLE CRIMINALS TO IMPACT OVER HALF A MILLION USERS AND GLOBAL BUSINESSES. Retrieved January 17, 2018.
  3. Wikipedia Man in the Browser Open source
    Wikipedia. (2017, October 28). Man-in-the-browser. Retrieved January 10, 2018.
  4. cobaltstrike manual Open source
    Strategic Cyber LLC. (2017, March 14). Cobalt Strike Manual. Retrieved May 24, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.