T1539 - Steal Web Session Cookie - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
December 11, 2025
Last Seen
July 23, 2026

T1539 - Steal Web Session Cookie is a mitre_attack tracked across 9 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed December 11, 2025; most recent activity July 23, 2026.

Overview

T1539 Steal Web Session Cookie involves stealing browser or web app session cookies to hijack authenticated sessions, enabling attackers to impersonate legitimate users and access apps without re-authentication. The technique often relies on malware or data exfiltration from browsers, and can undermine login controls and MFA protections if a valid session cookie is obtained. Recent reports tie StealC malware to this capability and highlight social-engineering delivery vectors that facilitate cookie-theft campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • T1539 — attack.mitre.org · July 23, 2026
  • MacOS malware hijacks Telegram sessions, targets crypto wallets — Feeds.Feedburner · July 17, 2026
  • Fileless Malware Abuses Google Blogspot to Deploy Infostealer in Memory — Infosecurity-Magazine · July 1, 2026
  • Yahoo: 'State-sponsored' actors behind biggest data breach ever — Digitaljournal · June 3, 2026
  • Introducing HAR Sanitizer: secure HAR sharing — blog.cloudflare.com · May 16, 2026
  • Na Lvivshhini Zatrimano Xakersku Grupu Yaka Zlamuvala Igrovi Akaunti I Otrimala Maize 10 Mln Grn Pributku Vid Yix Prodazu V Rosiyu — gp.gov.ua · April 29, 2026
  • Why Simple Breach Monitoring is No Longer Enough — Bleepingcomputer · April 6, 2026
  • Researchers Gain Access to StealC Malware Command-and — Cybersecuritynews · January 17, 2026

CVSS v3.1 Breakdown