Technique.View on attack.mitre.org
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of personal information about users (e.g., banking sites, relationships/interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
Browser information may also highlight additional targets after an adversary has access to valid credentials, especially Credentials In Files associated with logins cached by a browser.
Specific storage locations vary based on platform and/or application, but browser information is typically stored in local files and databases (e.g., `%APPDATA%/Google/Chrome`).
Rules on DetectionCode tagged with T1217.
| Rule | Level | Log source |
|---|---|---|
| Automated Collection Bookmarks Using Get-ChildItem PowerShell | low | windows / ps_script |
| File And SubFolder Enumeration Via Dir Command | low | windows / process_creation |
| Suspicious File Access to Browser Credential Storage | low | windows / file_access |
| Suspicious Where Execution | low | windows / process_creation |
| Used by | Procedure example |
|---|---|
| GroupAPT38 | APT38 has collected browser bookmark information to learn more about compromised hosts, obtain personal information about users, and acquire details about internal network resources. |
| GroupChimera | Chimera has used |
| GroupFox Kitten | Fox Kitten has used Google Chrome bookmarks to identify internal resources and assets. |
| GroupKimsuky | Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys. |
| GroupMoonstone Sleet | Moonstone Sleet deployed malware such as YouieLoader capable of capturing victim system browser information. |
| GroupScattered Spider | Scattered Spider retrieves browser histories via infostealer malware such as Raccoon Stealer. |
| GroupVolt Typhoon | Volt Typhoon has targeted the browsing history of network administrators. |
| Used by | Procedure example |
|---|---|
| MalwareBeaverTail | BeaverTail has searched the victim device for browser extensions including those commonly associated with cryptocurrency wallets. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Recorded Future Contagious Inteview BeaverTail InvisibleFerret OtterCookie February 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket HexEval BeaverTail Contagious Interview June 2025 |
| MalwareCalisto | Calisto collects information on bookmarks from Google Chrome. |
| MalwareCuckoo Stealer | Cuckoo Stealer can collect bookmarks, cookies, and history from Safari. |
| MalwareDarkWatchman | DarkWatchman can retrieve browser history. |
| MalwareDtrack | Dtrack can retrieve browser history. |
| ToolEmpire | Empire has the ability to gather browser data such as bookmarks and visited sites. |
| MalwareGlassWorm | GlassWorm has searched browser data for cookies, history, login databases, and cryptocurrency wallets. |
| MalwareLightSpy | To collect data on the host's Wi-Fi connection history, LightSpy reads the `/Library/Preferences/SystemConfiguration/com.apple.airport.preferences.plist` file. It also utilizes Apple's `CWWiFiClient` API to scan for nearby Wi-Fi networks and obtain data on the SSID, security type, and RSSI (signal strength) values. |
| Used by | Procedure example |
|---|---|
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus leveraged ICONICSTEALER to steal browser information to include browser history located on the infected host. |
| CampaignJuicy Mix | During Juicy Mix, OilRig used the CDumper (Chrome browser) and EDumper (Edge browser) data stealers to collect cookies, browsing history, and credentials. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace exported Chrome web data including contact information, keywords, autofill data, and stored credit card information. |
| CampaignOuter Space | During Outer Space, OilRig used a Chrome data dumper named MKG. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.