# T1185 Browser Session Hijacking

> As of 2026-10-05, T1185 (Browser Session Hijacking) appears in 83 tracked threats, first reported 2026-02-02 and most recently 2026-10-04, with linked actors including DarkSpectre, Magecart, Periwinkle Tempest; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 83 (13 critical, 66 high, 3 medium)
- **First seen:** 2026-02-02
- **Last seen:** 2026-10-04
- **Threat actors:** 14
- **Detection rules:** 112 (counts only; Blue tier and above)

## Key facts

- **ID:** T1185
- **Framework:** MITRE ATT&CK
- **Tactics:** Collection
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1185/

## Activity timeline

T1185 first appeared in tracked threats on 2026-02-02 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 28 reports, and 83 of the 83 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1185 Browser Session Hijacking is catalogued by MITRE ATT&CK under the Collection tactic in the Enterprise matrix. Threadlinqs maps 83 of 2623 tracked threats (3.2%) to it; by severity that is 13 critical, 66 high, 3 medium.

Threats that use T1185 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (55 threats), [T1539 Steal Web Session Cookie](https://intel.threadlinqs.com/technique/T1539) (51 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (43 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (40 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (39 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

14 tracked threat actors appear in the threats that use T1185; the most frequent are [DarkSpectre](https://intel.threadlinqs.com/actor/DarkSpectre) (2), [Magecart](https://intel.threadlinqs.com/actor/Magecart) (2), [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) (2), [APT28](https://intel.threadlinqs.com/actor/APT28) (1), [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) (1).

## Mitigations

MITRE ATT&CK lists 2 mitigations for T1185.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)

## Data sources

Telemetry that can reveal T1185, per MITRE ATT&CK.

- Logon Session — Logon Session Creation
- Process — Process Access, Process Modification

## Threat actors using it

- [DarkSpectre](https://intel.threadlinqs.com/actor/DarkSpectre) — 2
- [Magecart](https://intel.threadlinqs.com/actor/Magecart) — 2
- [Periwinkle Tempest](https://intel.threadlinqs.com/actor/Periwinkle%20Tempest) — 2
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 1
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 1
- [GlassWorm Operator](https://intel.threadlinqs.com/actor/GlassWorm%20Operator) — 1
- [Grandoreiro operators](https://intel.threadlinqs.com/actor/Grandoreiro%20operators) — 1
- [Payouts King](https://intel.threadlinqs.com/actor/Payouts%20King) — 1
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 1
- [REF9334](https://intel.threadlinqs.com/actor/REF9334) — 1
- [SHADOW-WATER-063](https://intel.threadlinqs.com/actor/SHADOW-WATER-063) — 1

## Tracked threats

The 30 most recent of 83 tracked threats that use T1185.

- [Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…](https://intel.threadlinqs.com/threat/TL-2026-2894) — critical — 2026-10-04
- [Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)](https://intel.threadlinqs.com/threat/TL-2026-2717) — high — 2026-09-27
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [KREMLIN Banking Malware Forges Chrome/Edge Secure Preferences Integrity Checks to Force-Install Malicious…](https://intel.threadlinqs.com/threat/TL-2026-2544) — high — 2026-09-16
- [BigBear 2.0 Evilginx2 Phishing-as-a-Service Campaign Targeting Microsoft 365 with MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-2374) — critical — 2026-09-07
- [BlueKit Phishing-as-a-Service Adds ZeroBot Bot-Screening and ScreenConnect Delivery to Target…](https://intel.threadlinqs.com/threat/TL-2026-2315) — high — 2026-09-03
- [Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2235) — high — 2026-08-30
- [TrickBot injectDLL Module: Man-in-the-Browser Web Injection Against Certificate Transparency](https://intel.threadlinqs.com/threat/TL-2026-2133) — high — 2026-08-24
- [CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenames](https://intel.threadlinqs.com/threat/TL-2026-2043) — medium — 2026-08-17
- [AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Control](https://intel.threadlinqs.com/threat/TL-2026-2029) — high — 2026-08-16
- [Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader…](https://intel.threadlinqs.com/threat/TL-2026-1976) — high — 2026-08-10
- [WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638)](https://intel.threadlinqs.com/threat/TL-2026-1933) — high — 2026-08-07
- [XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode Projects](https://intel.threadlinqs.com/threat/TL-2026-1870) — high — 2026-08-04
- [XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…](https://intel.threadlinqs.com/threat/TL-2026-1792) — high — 2026-07-31
- [Astaroth (Guildma) Banking Trojan Adds WhatsApp Web Spambot Module — STAC3150 / "Boto Cor-de-Rosa" Campaign…](https://intel.threadlinqs.com/threat/TL-2026-1785) — high — 2026-07-31
- [OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-1783) — high — 2026-07-31
- [Adform Ad-Tech Platform Compromised: Supply-Chain Injection Serves Clipboard Crypto Stealer via…](https://intel.threadlinqs.com/threat/TL-2026-1775) — high — 2026-07-30
- [MedusaHVNC — Hidden Virtual Desktop RAT with AMSI/ETW Bypass and Multi-Browser Session Hijacking](https://intel.threadlinqs.com/threat/TL-2026-1733) — high — 2026-07-27
- [MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal…](https://intel.threadlinqs.com/threat/TL-2026-1723) — high — 2026-07-27
- [npm Supply-Chain Compromise (chalk/debug + 17 packages, Sept 2025) — Motivates GitHub Dependabot 'Cooldown'…](https://intel.threadlinqs.com/threat/TL-2026-1714) — high — 2026-07-27
- [ChonkyChicken RAT (TAG-195/Golden Chickens) Bypasses Chrome App-Bound Encryption via ChromEggscalator to…](https://intel.threadlinqs.com/threat/TL-2026-1664) — high — 2026-07-24
- [TrickBot Malware Variant Adopts DNS Tunneling for C2 Communications (westurn.in)](https://intel.threadlinqs.com/threat/TL-2026-1651) — high — 2026-07-23
- [CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web…](https://intel.threadlinqs.com/threat/TL-2026-1637) — high — 2026-07-22
- [Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through…](https://intel.threadlinqs.com/threat/TL-2026-1605) — high — 2026-07-22
- [ClickFix Campaign Delivers TELEPUZ Modular RAT via VIDAR-Based Second Stage](https://intel.threadlinqs.com/threat/TL-2026-1558) — high — 2026-07-20
- [TELEPUZ: Modular MaaS Banking WebInjector Distributed via ClickFix/VIDAR Chain](https://intel.threadlinqs.com/threat/TL-2026-1557) — high — 2026-07-20
- [Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure…](https://intel.threadlinqs.com/threat/TL-2026-1501) — high — 2026-07-18
- [TELEPUZ Malware-as-a-Service Spreads via ClickFix Attacks and Go-Variant Vidar Stealer Chain](https://intel.threadlinqs.com/threat/TL-2026-1420) — high — 2026-07-16
- [The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWorm](https://intel.threadlinqs.com/threat/TL-2026-1418) — high — 2026-07-16
- [PhantomEnigma Campaign: 20+ Hijacked Brazilian Government Websites Distribute Banking Backdoor via Patched…](https://intel.threadlinqs.com/threat/TL-2026-1416) — high — 2026-07-16

## Related CVEs

CVEs referenced by the tracked threats that use T1185, most frequent first.

- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2017-11882](https://intel.threadlinqs.com/cve/CVE-2017-11882)
- [CVE-2017-8570](https://intel.threadlinqs.com/cve/CVE-2017-8570)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2023-36899](https://intel.threadlinqs.com/cve/CVE-2023-36899)
- [CVE-2025-66376](https://intel.threadlinqs.com/cve/CVE-2025-66376)
- [CVE-2026-103922](https://intel.threadlinqs.com/cve/CVE-2026-103922)
- [CVE-2026-12044](https://intel.threadlinqs.com/cve/CVE-2026-12044)
- [CVE-2026-12437](https://intel.threadlinqs.com/cve/CVE-2026-12437)
- [CVE-2026-12438](https://intel.threadlinqs.com/cve/CVE-2026-12438)
- [CVE-2026-12439](https://intel.threadlinqs.com/cve/CVE-2026-12439)
- [CVE-2026-12440](https://intel.threadlinqs.com/cve/CVE-2026-12440)
- [CVE-2026-12441](https://intel.threadlinqs.com/cve/CVE-2026-12441)
- [CVE-2026-12442](https://intel.threadlinqs.com/cve/CVE-2026-12442)
- [CVE-2026-15107](https://intel.threadlinqs.com/cve/CVE-2026-15107)
- [CVE-2026-15129](https://intel.threadlinqs.com/cve/CVE-2026-15129)
- [CVE-2026-15130](https://intel.threadlinqs.com/cve/CVE-2026-15130)
- [CVE-2026-15131](https://intel.threadlinqs.com/cve/CVE-2026-15131)
- [CVE-2026-15132](https://intel.threadlinqs.com/cve/CVE-2026-15132)
- [CVE-2026-15899](https://intel.threadlinqs.com/cve/CVE-2026-15899)
- [CVE-2026-15900](https://intel.threadlinqs.com/cve/CVE-2026-15900)
- [CVE-2026-15901](https://intel.threadlinqs.com/cve/CVE-2026-15901)
- [CVE-2026-15902](https://intel.threadlinqs.com/cve/CVE-2026-15902)
- [CVE-2026-15903](https://intel.threadlinqs.com/cve/CVE-2026-15903)

## Detection coverage

Threadlinqs maintains 112 detection rules mapped to T1185 (SPL 35, KQL 40, Sigma 37). Rule content is available to Blue tier accounts and above; this page shows counts only.

112 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1185
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
