# T1539 Steal Web Session Cookie

> As of 2026-10-05, T1539 (Steal Web Session Cookie) appears in 461 tracked threats, first reported 2025-10-13 and most recently 2026-10-04, with linked actors including APT38, Andariel, Lazarus Group; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 461 (89 critical, 323 high, 44 medium, 3 low)
- **First seen:** 2025-10-13
- **Last seen:** 2026-10-04
- **Threat actors:** 104
- **Detection rules:** 579 (counts only; Blue tier and above)

## Key facts

- **ID:** T1539
- **Framework:** MITRE ATT&CK
- **Tactics:** Credential Access
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1539/

## Activity timeline

T1539 first appeared in tracked threats on 2025-10-13 and was most recently reported on 2026-10-04. The busiest month was 2026-07 with 161 reports, and 460 of the 461 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1539 Steal Web Session Cookie is catalogued by MITRE ATT&CK under the Credential Access tactic in the Enterprise matrix. Threadlinqs maps 461 of 2623 tracked threats (17.6%) to it; by severity that is 89 critical, 323 high, 44 medium, 3 low.

Threats that use T1539 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (287 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (281 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (231 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (228 threats), [T1566 Phishing](https://intel.threadlinqs.com/technique/T1566) (191 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

104 tracked threat actors appear in the threats that use T1539; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (9), [Andariel](https://intel.threadlinqs.com/actor/Andariel) (6), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (6), [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) (6), [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) (6).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1539.

- [M1017 User Training](https://attack.mitre.org/mitigations/M1017/)
- [M1021 Restrict Web-Based Content](https://attack.mitre.org/mitigations/M1021/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)
- [M1051 Update Software](https://attack.mitre.org/mitigations/M1051/)
- [M1054 Software Configuration](https://attack.mitre.org/mitigations/M1054/)

## Data sources

Telemetry that can reveal T1539, per MITRE ATT&CK.

- File — File Access
- Process — Process Access

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 9
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 6
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 6
- [Scattered LAPSUS$ Hunters](https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters) — 6
- [Scattered Spider](https://intel.threadlinqs.com/actor/Scattered%20Spider) — 6
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 6
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 6
- [The Com](https://intel.threadlinqs.com/actor/The%20Com) — 6
- [UNC6671](https://intel.threadlinqs.com/actor/UNC6671) — 6
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 5
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 5
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 5

## Tracked threats

The 30 most recent of 461 tracked threats that use T1539.

- [Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code…](https://intel.threadlinqs.com/threat/TL-2026-2912) — critical — 2026-10-04
- [Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features…](https://intel.threadlinqs.com/threat/TL-2026-2894) — critical — 2026-10-04
- [China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing (Frameless BitB)](https://intel.threadlinqs.com/threat/TL-2026-2884) — high — 2026-10-04
- [Atomic macOS (AMOS) Stealer Delivered via Malicious Ad Impersonating Claude Code (ClickFix-style)](https://intel.threadlinqs.com/threat/TL-2026-2916) — high — 2026-10-02
- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [MALFEX: Malicious npm postinstall supply-chain campaign delivering Overlord RAT and movinlike stealer](https://intel.threadlinqs.com/threat/TL-2026-2801) — high — 2026-09-30
- [Star Blizzard (SEABORGIUM) RedFlick technique: scheduled-task backdoor delivery via phishing (CosmicPulse)](https://intel.threadlinqs.com/threat/TL-2026-2787) — high — 2026-09-29
- [Infostealer-Stolen AI Service Logins Expose 80,000+ Corporate Domains (Shadow AI to LLMjacking)](https://intel.threadlinqs.com/threat/TL-2026-2757) — high — 2026-09-28
- [Infostealers Target Corporate AI Accounts, Sessions and API Keys (LLMjacking Risk)](https://intel.threadlinqs.com/threat/TL-2026-2752) — high — 2026-09-28
- [GitHub Security Lab AI Agent Uncovers 24 Android App Vulnerabilities, Including OsmAnd Location-Tracking…](https://intel.threadlinqs.com/threat/TL-2026-2744) — medium — 2026-09-28
- [MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto…](https://intel.threadlinqs.com/threat/TL-2026-2723) — high — 2026-09-27
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [The Infostealer Incursion: Stolen Credentials Breach Cloud, Code, and AI Environments](https://intel.threadlinqs.com/threat/TL-2026-2687) — high — 2026-09-27
- [x47.c Windows Botnet-as-a-Service Weaponizes xAI Grok for AI-Assisted Persistence and AI API Credit Draining](https://intel.threadlinqs.com/threat/TL-2026-2686) — high — 2026-09-27
- [PamStealer macOS Infostealer Adds Live C2 with X25519 Key Exchange, Four-Method Persistence](https://intel.threadlinqs.com/threat/TL-2026-2674) — high — 2026-09-26
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Lunex Stealer Abuses Vulnerable AMD Radeon Driver (CVE-2023-20598) to Blind Security Monitoring and Steal…](https://intel.threadlinqs.com/threat/TL-2026-2664) — high — 2026-09-26
- [Vexy Ransomware Claims Data-Extortion Attack on Majani Insurance Brokers (Kenya)](https://intel.threadlinqs.com/threat/TL-2026-2713) — medium — 2026-09-25
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-2680) — critical — 2026-09-25
- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…](https://intel.threadlinqs.com/threat/TL-2026-2658) — medium — 2026-09-25
- [Cross-tenant data exposure in Cloudflare Containers/Sandboxes/Browser Run via Linux dm-thin…](https://intel.threadlinqs.com/threat/TL-2026-2648) — high — 2026-09-25
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25
- [MacSync macOS infostealer abuses public iCloud calendars as a command channel to deliver a new backdoor module](https://intel.threadlinqs.com/threat/TL-2026-2641) — high — 2026-09-24
- [CISA KEV Additions (2026-09-24): WSO2 JWT Authentication Bypass (CVE-2026-5430, CVSS 10.0) and Adobe…](https://intel.threadlinqs.com/threat/TL-2026-2640) — critical — 2026-09-24
- [MacSync macOS infostealer/backdoor: reworked MaaS chain stages stage-two via a public iCloud calendar…](https://intel.threadlinqs.com/threat/TL-2026-2637) — high — 2026-09-24
- [Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated](https://intel.threadlinqs.com/threat/TL-2026-2598) — high — 2026-09-21
- [Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing…](https://intel.threadlinqs.com/threat/TL-2026-2563) — critical — 2026-09-18
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18

## Related CVEs

CVEs referenced by the tracked threats that use T1539, most frequent first.

- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-3055](https://intel.threadlinqs.com/cve/CVE-2026-3055)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-4368](https://intel.threadlinqs.com/cve/CVE-2026-4368)
- [CVE-2026-8451](https://intel.threadlinqs.com/cve/CVE-2026-8451)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2020-28707](https://intel.threadlinqs.com/cve/CVE-2020-28707)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2023-7028](https://intel.threadlinqs.com/cve/CVE-2023-7028)
- [CVE-2024-42009](https://intel.threadlinqs.com/cve/CVE-2024-42009)
- [CVE-2025-27152](https://intel.threadlinqs.com/cve/CVE-2025-27152)
- [CVE-2025-53521](https://intel.threadlinqs.com/cve/CVE-2025-53521)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-10816](https://intel.threadlinqs.com/cve/CVE-2026-10816)
- [CVE-2026-10817](https://intel.threadlinqs.com/cve/CVE-2026-10817)
- [CVE-2026-13474](https://intel.threadlinqs.com/cve/CVE-2026-13474)
- [CVE-2026-1357](https://intel.threadlinqs.com/cve/CVE-2026-1357)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-3909](https://intel.threadlinqs.com/cve/CVE-2026-3909)
- [CVE-2026-3910](https://intel.threadlinqs.com/cve/CVE-2026-3910)
- [CVE-2026-41940](https://intel.threadlinqs.com/cve/CVE-2026-41940)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)

## Detection coverage

Threadlinqs maintains 579 detection rules mapped to T1539 (SPL 178, KQL 221, Sigma 180). Rule content is available to Blue tier accounts and above; this page shows counts only.

579 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1539
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
