Tag
high
threat
Suspicious File Download via Headless Browser
1 rule 2 TTPs 26 IOCsThe DUCKTAIL threat actor leverages Chromium-based web browsers (such as Microsoft Edge and Chrome) running in headless mode with the `--dump-dom` argument to stealthily download malicious content from the internet via suspicious file-sharing domains, impacting compromised endpoints.
Brave Browser +4
DUCKTAIL
headless-browser
file-download
data-exfiltration
malware-delivery
endpoint
network
1r
2t
26i
high
advisory
Potential File Download via a Headless Browser
2 rules 1 TTPDetects the execution of headless browsers from suspicious parent processes with arguments indicative of scripted retrieval, bypassing application control policies and restrictions on direct download tools.
command-and-control
headless-browser
file-download
windows
2r
1t
medium
advisory
Suspicious File Download via Headless Browser
2 rules 2 TTPs 26 IOCsAttackers are leveraging Chromium-based browsers in headless mode with the `--dump-dom` argument to download files from file-sharing services and direct IPs, potentially indicative of reconnaissance or malware delivery.
Chrome +2
headless-browser
file-download
cisco-nvm
2r
2t
26i