T1539 - Steal Web Session Cookie - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
20
occurrences
First Seen
December 11, 2025
Last Seen
September 9, 2026

Related Threat Clusters

  • Yahoo Confirms Breach of Over 1 Billion Accounts Linked to State-Sponsored Actors

    Yahoo has disclosed a massive data breach affecting more than one billion user accounts, which occurred in August 2013. This breach is separate from a previously reported incident in 2014 that compromised 500 million…

    3 articles · Updated June 3, 2026
  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • Multiple Critical CVEs Exploited in Cybersecurity Attacks

    A series of vulnerabilities, including CVE-2025-49144, CVE-2025-31702, and CVE-2026-46333, have been identified, affecting systems like Notepad++ and FortiWeb devices. These vulnerabilities allow for local privilege…

    30 articles · Updated September 7, 2026
  • Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data

    Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the…

    4 articles · Updated August 31, 2026
  • BigBear 2.0 Phishing Campaign Targets Microsoft 365 Users

    The BigBear 2.0 phishing-as-a-service campaign has compromised over 5,137 Microsoft 365 credentials from 258 organizations, utilizing an Evilginx2-based framework to bypass multi-factor authentication (MFA). Discovered…

    10 articles · Updated September 7, 2026
  • Infostealer Malware Hijacks Claude Sessions, Drains User Accounts

    Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication.…

    44 articles · Updated August 31, 2026
  • macOS Malware Hijacks Telegram Sessions to Steal Crypto Wallet Data

    Security researchers have identified a new macOS malware that targets cryptocurrency users by hijacking Telegram Desktop sessions. This malware extracts sensitive information from local files, including passwords,…

    7 articles · Updated July 17, 2026
  • Fileless PureLog Stealer Campaign Exploits Compromised Websites

    A sophisticated cyber campaign is leveraging compromised websites and a malicious JavaScript file named transcript.pdf.js to deploy PureLog Stealer, a .NET-based infostealer. The attack uses a fileless infection method,…

    5 articles · Updated July 3, 2026
  • LockBit Ransomware Targets ICBC Financial Services and U.S. Bank

    On November 8, 2025, the LockBit ransomware group attacked ICBC Financial Services, disrupting U.S. Treasury trading operations. The attack exploited a vulnerability in Citrix NetScaler, leading to a $9 billion…

    10 articles · Updated August 20, 2026
  • Enterprises Struggle with Stolen Credential Threats in 2026

    In 2026, stolen credentials are identified as a critical cybersecurity risk, with 85% of organizations ranking them as a high priority. Despite this, many enterprises rely on inadequate checkbox solutions and generic…

    2 articles · Updated April 6, 2026

Recent Intelligence Reports

  • SpyCloud 2026 Identity Threat Report Finds Non — Markets.Businessinsider · September 9, 2026
  • BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft — Cybersecuritynews · September 8, 2026
  • CVE-2025 — Sploitus · September 7, 2026
  • Anthropic Users Hit by Infostealer Attacks, Session Thefts — Darkreading · August 31, 2026
  • Anthropic Warning: Infostealer Malware Is Hijacking Claude Sessions, Draining Accounts — Esecurityplanet · August 31, 2026
  • Anthropic cracks down on hijacked user accounts mining AI tokens — Theregister · August 31, 2026
  • Amp — www.bleepingcomputer.com · August 31, 2026
  • Anthropic Warns Commodity Infostealers Are Hijacking Claude Sessions to Drain Paid Usage — Thecyberexpress · August 31, 2026

CVSS v3.1 Breakdown