Skip to content
Threat Feed
high threat

Suspicious File Download via Headless Browser

The DUCKTAIL threat actor leverages Chromium-based web browsers (such as Microsoft Edge and Chrome) running in headless mode with the `--dump-dom` argument to stealthily download malicious content from the internet via suspicious file-sharing domains, impacting compromised endpoints.

Since at least 2025, the DUCKTAIL threat actor has been observed utilizing a deceptive technique involving headless Chromium-based browsers like Microsoft Edge, Google Chrome, Brave, Opera, and Vivaldi. This method automates the download of content from suspicious internet sources using direct URLs or known file-sharing platforms. By launching browsers in --headless mode and employing the --dump-dom argument, DUCKTAIL aims to covertly retrieve additional tools, malware, or sensitive data onto compromised systems without visual user interaction. This tactic enables attackers to maintain a low profile while escalating their control or exfiltrating information, making detection challenging without specific network and process monitoring. The technique relies on the browser's ability to render web content and dump its Document Object Model, which can be leveraged to retrieve various file types.

Attack Chain

  1. An attacker's tool or script executes a Chromium-based web browser (e.g., chrome.exe, msedge.exe, brave.exe, opera.exe, vivaldi.exe) on a compromised endpoint.
  2. The browser is launched with specific command-line arguments, including --headless, indicating it should run without a visible user interface.
  3. The --dump-dom command-line argument is supplied to the browser, instructing it to render a specified URL and output its Document Object Model, which can be used to capture or retrieve content.
  4. The headless browser initiates an outbound network connection to a specified malicious URL or a suspicious file-sharing domain (e.g., anonfiles.com, cdn.discordapp.com, githubusercontent.com).
  5. The browser stealthily downloads content from the remote server, which may include malware, additional stage tools, or files for exfiltration.
  6. The downloaded content is then utilized for subsequent phases of the DUCKTAIL campaign, such as credential harvesting, data exfiltration, or further system compromise.

Impact

Successful exploitation allows attackers, such as DUCKTAIL, to download additional malicious payloads, maintain persistence, exfiltrate sensitive data, or install infostealers. The stealthy nature of this technique makes it difficult for users to detect, potentially leading to prolonged compromise and significant data breaches. DUCKTAIL campaigns have historically targeted individuals and businesses, primarily focusing on information theft, especially credentials for social media and business platforms, leading to financial fraud and intellectual property theft.

Recommendation

  • Deploy the Sigma rule provided in this brief to your SIEM and tune for your environment to detect suspicious headless browser activity.
  • Ensure Cisco Network Visibility Module logs are collected and ingested into your SIEM platform to facilitate detection based on network flow data.
  • Implement network egress filtering to block connections to the suspicious file-sharing domains listed in the IOC table.
  • Monitor process creation and command-line arguments for browser executables to identify --headless and --dump-dom usage from unexpected processes or user contexts.

Detection coverage 1

Detect Suspicious File Download via Headless Chromium Browser

high

Detects Chromium-based browsers (Edge, Chrome, Brave, Opera, Vivaldi) running in headless mode with `--dump-dom` argument, connecting to suspicious file-sharing or hosting domains, a technique observed in DUCKTAIL campaigns.

sigma tactics: command_and_control, execution techniques: T1059, T1105 sources: network_connection, windows

Detection queries are available on the platform. Get full rules →

Indicators of compromise

26

domain

TypeValue
domaingithubusercontent.com
domainanonfiles.com
domaincdn.discordapp.com
domainddns.net
domaindl.dropboxusercontent.com
domainghostbin.co
domainglitch.me
domaingofile.io
domainhastebin.com
domainmediafire.com
domainmega.nz
domainonrender.com
domainpages.dev
domainpaste.ee
domainpastetext.net
domainsend.exploit.in
domainsendspace.com
domainstorage.googleapis.com
domainstorjshare.io
domainsupabase.co
domaintemp.sh
domaintransfer.sh
domaintrycloudflare.com
domainufile.io
domainw3spaces.com
domainworkers.dev