T1539 - Steal Web Session Cookie is a mitre_attack tracked across 9 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed December 11, 2025; most recent activity July 23, 2026.
T1539 Steal Web Session Cookie involves stealing browser or web app session cookies to hijack authenticated sessions, enabling attackers to impersonate legitimate users and access apps without re-authentication. The technique often relies on malware or data exfiltration from browsers, and can undermine login controls and MFA protections if a valid session cookie is obtained. Recent reports tie StealC malware to this capability and highlight social-engineering delivery vectors that facilitate cookie-theft campaigns.
Yahoo has disclosed a massive data breach affecting more than one billion user accounts, which occurred in August 2013. This breach is separate from a previously reported incident in 2014 that compromised 500 million…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
Security researchers have identified a new macOS malware that targets cryptocurrency users by hijacking Telegram Desktop sessions. This malware extracts sensitive information from local files, including passwords,…
A sophisticated cyber campaign is leveraging compromised websites and a malicious JavaScript file named transcript.pdf.js to deploy PureLog Stealer, a .NET-based infostealer. The attack uses a fileless infection method,…
In 2026, stolen credentials are identified as a critical cybersecurity risk, with 85% of organizations ranking them as a high priority. Despite this, many enterprises rely on inadequate checkbox solutions and generic…
Ukrainian authorities arrested three individuals involved in hijacking over 610,000 Roblox accounts, with an estimated profit of $225,000 from their illegal sales. The group, led by a 19-year-old, used malware disguised…
On October 18, 2023, Cloudflare detected an attack originating from a compromised authentication token at Okta. The attackers accessed Cloudflare's Okta instance using session tokens from support tickets, but no…
Security researchers exploited vulnerabilities in the StealC malware infrastructure, gaining access to operator control panels. This breach exposed a threat actor's identity through their own stolen session cookies,…
Attackers are utilizing professional-looking animations to deceive users into downloading malware. The HP Threat Research report details how these campaigns leverage purchasable malware tools and techniques to evade…