Activity timeline
T1539 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 161 reports, and 460 of the 461 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1539 Steal Web Session Cookie is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 461 of 2623 tracked threats (17.6%) to it; by severity that is 89 critical, 323 high, 44 medium, 3 low.
Threats that use T1539 most often also use T1005 Data from Local System (287 threats), T1027 Obfuscated Files or Information (281 threats), T1041 Exfiltration Over C2 Channel (231 threats), T1082 System Information Discovery (228 threats), T1566 Phishing (191 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
104 tracked threat actors appear in the threats that use T1539; the most frequent are APT38 (9), Andariel (6), Lazarus Group (6), Scattered LAPSUS$ Hunters (6), Scattered Spider (6).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1539.
Data sources
Telemetry that can reveal T1539, per MITRE ATT&CK.
- File — File Access
- Process — Process Access
Threat actors using it
Tracked threats
The 30 most recent of 461 tracked threats that use T1539.
- Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code…critical
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…critical
- China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)high
- Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)high
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealerhigh
- Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)high
- Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)high
- Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)high
- GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking…medium
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…high
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…medium
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environmentshigh
- x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draininghigh
- PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistencehigh
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…high
- Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)medium
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…critical
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…medium
- Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin…high
- TokenGrabber: Python-based MaaS Infostealer Builderhigh
- MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor modulehigh
- CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe…critical
- MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…high
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltratedhigh
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing…critical
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
Detection coverage
Threadlinqs maintains 579 detection rules mapped to T1539 (SPL 178, KQL 221, Sigma 180). Rule content is available to Blue tier accounts and above; this page shows counts only.