Activity timeline
T1185 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 28 reports, and 83 of the 83 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1185 Browser Session Hijacking is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 83 of 2623 tracked threats (3.2%) to it; by severity that is 13 critical, 66 high, 3 medium.
Threats that use T1185 most often also use T1027 Obfuscated Files or Information (55 threats), T1539 Steal Web Session Cookie (51 threats), T1036 Masquerading (43 threats), T1041 Exfiltration Over C2 Channel (40 threats), T1005 Data from Local System (39 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
14 tracked threat actors appear in the threats that use T1185; the most frequent are DarkSpectre (2), Magecart (2), Periwinkle Tempest (2), APT28 (1), BlueDelta (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1185.
Data sources
Telemetry that can reveal T1185, per MITRE ATT&CK.
- Logon Session — Logon Session Creation
- Process — Process Access, Process Modification
Threat actors using it
Tracked threats
The 30 most recent of 83 tracked threats that use T1185.
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…critical
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)high
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…high
- BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypasscritical
- BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…high
- Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…high
- TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate Transparencyhigh
- CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenamesmedium
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader…high
- WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638)high
- XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projectshigh
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…high
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- Adform Ad-Tech Platform Compromised: Supply-Chain Injection Serves Clipboard Crypto Stealer via…high
- MedusaHVNC — Hidden Virtual Desktop RAT with AMSI/ETW Bypass and Multi-Browser Session Hijackinghigh
- MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal…high
- npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown'…high
- ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…high
- TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)high
- CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web…high
- Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through…high
- ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stagehigh
- TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chainhigh
- Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure…high
- TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chainhigh
- The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWormhigh
- PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…high
Detection coverage
Threadlinqs maintains 112 detection rules mapped to T1185 (SPL 35, KQL 40, Sigma 37). Rule content is available to Blue tier accounts and above; this page shows counts only.