Activity timeline
T1217 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 22 reports, and 68 of the 68 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1217 Browser Information Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 68 of 2623 tracked threats (2.6%) to it; by severity that is 12 critical, 50 high, 6 medium.
Threats that use T1217 most often also use T1005 Data from Local System (57 threats), T1027 Obfuscated Files or Information (48 threats), T1082 System Information Discovery (48 threats), T1539 Steal Web Session Cookie (45 threats), T1041 Exfiltration Over C2 Channel (44 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
21 tracked threat actors appear in the threats that use T1217; the most frequent are APT38 (6), Lazarus Group (5), Contagious Interview (4), Sapphire Sleet (4), Stardust Chollima (4).
Data sources
Telemetry that can reveal T1217, per MITRE ATT&CK.
- Command — Command Execution
- File — File Access
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 68 tracked threats that use T1217.
- Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…high
- Poper Blocker Chrome Extension Spyware: Big Star Labs' 'Featured' Ad Blocker Exfiltrates Browsing History…high
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Smishing Triad "Outsider" Operator: JWR Phishing Kit's AES-256-CTR WebSocket Exfiltration Cockpithigh
- PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Executionhigh
- Commodity Infostealers Hijack Authenticated Claude Sessions to Drain Usage and Payment Methodsmedium
- Anthropic Locks Out Claude Users After Commodity Infostealers (Vidar, LummaC2, StealC, RedLine, Acreed…medium
- BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operationhigh
- Superior Campaign: 19 Chrome and Edge Extensions Weaponized to Drain Crypto Wallets and Steal…high
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Sidehigh
- Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader…high
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…high
- GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC…medium
- Atomic MacOS (AMOS) Stealer Infection via Fake "macOS Toolkit" Terminal Commandmedium
- ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…high
- North Korean UNC5342 EtherHiding Campaign: Node.js RAT Delivered via Fake macOS Update Lures Using Ethereum…high
- XCSSET v40: Fileless macOS Xcode-Supply-Chain Malware Adds Chrome DevTools Protocol Hijacking and Telegram…high
- OctLurk and SilkLurk Backdoors: Unattributed Chinese-Speaking Actor Cyberespionage Campaign Targeting…high
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- BlueNoroff Fake Meeting Kit Captures Webcams, Disables Windows Defender, and Steals Cryptocurrency…high
- Dolphin X Stealer: AI-Profiled Windows Infostealer/RAT Targeting 300+ Applicationshigh
- Stealer Logs: Infostealer Malware Ecosystem Fuels Credential-Theft Economy (LummaC2, Rhadamanthys, Vidar…high
- RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan…high
- CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web…high
- Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through…high
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- UAC-0145 (Sandworm/APT44, GRU) Uses ClickFix Fake-CAPTCHA Lures and EtherHiding to Deploy Multi-Stage…high
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM…critical
- ClickLock Stealer: ClickFix-Delivered macOS Infostealer with GSocket Reverse-Shell Backdoorhigh
- Millenium RAT v4: C++ Rewrite Fuels Y2K Operators' MaaS Campaign (62,289 Devices, 160+ Countries)high
Detection coverage
Threadlinqs maintains 50 detection rules mapped to T1217 (SPL 13, KQL 25, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.