Tag
Credential Access via Chromium Remote Debugging
1 rule 1 TTPAdversaries can exploit Chromium-based browser remote debugging features to extract authentication cookies and hijack active web sessions.
Chromium V8 Engine Out-of-Bounds Memory Access Vulnerability
1 CVECVE-2026-0899 is an out-of-bounds memory access vulnerability in the Chromium V8 JavaScript engine that may result in memory corruption, process crashes, or arbitrary code execution.
Phishing Campaign Leveraging Blob URLs and Microsoft Teams Redirects
2 TTPs 1 IOCThreat actors are using legitimate Microsoft Teams redirects to chain external resources and generate dynamic, browser-resident phishing pages via blob URLs to bypass static URL scanning.
Detection of Browser-Spawned Unix Shells with External Connectivity
1 TTPAnomalous execution pattern where Unix-based browser processes spawn shells to initiate outbound external network connections, a TTP indicative of potential drive-by exploitation or browser-based post-exploitation.
Entra ID PRT Extraction via BrowserCore.exe Abuse
1 rule 2 TTPsAdversaries are abusing the legitimate BrowserCore.exe component to perform unauthorized extraction of Entra ID Primary Refresh Tokens (PRTs) by invoking the binary outside of expected browser-managed contexts.
Active Exploitation of Google Chromium V8 Type Confusion Vulnerability
1 TTP 2 CVEsA type confusion vulnerability in the Google Chromium V8 engine is being actively exploited in the wild, allowing remote attackers to achieve arbitrary code execution within the sandbox environment via crafted HTML pages.
Chrome VPN Extension Persistence via Registry Modification
1 rule 1 TTPAdversaries can gain persistence or bypass network controls by installing unauthorized Chrome VPN extensions through the Windows Registry.
Multiple Vulnerabilities in Google Chrome and Microsoft Edge
1 TTP 2 CVEsMultiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.
Jewelbug APT Dual-Purpose Espionage and Fraud Operations
3 TTPsJewelbug, a China-linked mercenary APT, uses a custom C2 platform called XG-Web to conduct both state-sponsored espionage and large-scale cryptocurrency theft using custom backdoors and malicious browser extensions.
Pass-ta-key Attacks Targeting Google Chrome Passkey Implementation
1 TTPResearchers identified multiple techniques allowing malware on Windows hosts to hijack Google-synced passkeys by extracting cryptographic material and forging authentication assertions.