Full Report
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]
Analysis Summary
# Tool/Technique: Browser-Based Evasion & SaaS-Heavy Attacks
## Overview
This set of techniques focuses on bypassing Endpoint Detection and Response (EDR) telemetry by operating entirely within the browser and cloud/SaaS environments. Because these attacks leverage legitimate browser processes, authenticated sessions, and OAuth tokens, they often fail to create the traditional host-based artifacts (such as malicious executables or unusual process trees) that EDR tools are designed to monitor.
## Technical Details
- **Type**: Technique / Attack Vector
- **Platform**: Web Browsers (Chrome, Edge, etc.), SaaS Environments (Microsoft 365, Salesforce, Workday, Drift)
- **Capabilities**: Session hijacking, credential theft, OAuth token abuse, data exfiltration via API, and malicious browser extension deployment.
- **First Seen**: Ongoing; specifically referenced campaigns in 2025 and 2026.
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.002 - Phishing: Spearphishing Link (AiTM)
- **TA0006 - Credential Access**
- T1557 - Adversary-in-the-Middle
- T1539 - Steal Web Session Cookie
- **TA0003 - Persistence**
- T1176 - Browser Extensions
- **TA0010 - Exfiltration**
- T1567 - Exfiltration Over Web Service
## Functionality
### Core Capabilities
- **Adversary-in-the-Middle (AiTM):** Phishing infrastructure proxies authentication in real-time, capturing credentials and session cookies even when MFA is present (unless FIDO2 is used).
- **Session Replay:** Stolen session IDs and OAuth tokens are used from attacker-controlled infrastructure to impersonate users without needing to re-authenticate.
- **API Abuse:** Using stolen OAuth tokens to make high-volume API calls against SaaS environments (e.g., Salesforce) to exfiltrate data.
### Advanced Features
- **Browser Extension Manipulation:** Using standard browser APIs to read page content, capture keystrokes, or exfiltrate data while remaining resident within a legitimate browser process (e.g., chrome.exe).
- **Search Engine Poisoning:** Redirecting users to malicious clones of legitimate login portals (e.g., Office 365) via malicious ads.
- **Context Switching:** Attackers may switch user agents (e.g., from a browser to "Axios") once a token is stolen to automate exfiltration.
## Indicators of Compromise
- **File Hashes:** N/A (Focus is on fileless/browser-based activity).
- **File Names:** Malicious `.crx` files (Chrome extensions) or modified browser profile files.
- **Network Indicators:**
- `Axios` user-agent strings appearing in SaaS logs for sessions originally created via standard browsers.
- Unexpected source IPs for authenticated sessions.
- **Behavioral Indicators:**
- High-volume API calls to CRM or ERP platforms following a new login.
- Creation of inbox rules (e.g., in Outlook) to hide banking or security notifications.
- Discrepancies between the session ID origin and the subsequent request origin.
## Associated Threat Actors
- **UNC6395**: Known for OAuth token abuse against Salesforce integrations.
- **Storm-2755 (Microsoft designation)**: Known for AiTM payroll pirate attacks targeting Canadian employees.
## Detection Methods
- **Identity Logs:** Monitoring for "impossible travel" or sudden changes in User Agent strings for active sessions.
- **SaaS API Monitoring:** Detecting anomalous volumes of data export or API requests.
- **Browser Monitoring:** Using specialized browser security tools (like NordLayer Browser) to inspect extension behavior and clipboard actions.
- **Network Level:** Inspecting traffic for known AiTM proxy domains.
## Mitigation Strategies
- **Phishing-Resistant MFA:** Implement FIDO2/WebAuthn to cryptographically tie authentication to legitimate origins.
- **Extension Policies:** Use GPO or browser management tools to allowlist only approved extensions and block all others.
- **Conditional Access:** Restrict SaaS access to dedicated, company-controlled IPs or compliant devices.
- **Browser Isolation:** Use secure browser solutions to encapsulate web activity and prevent interaction with the underlying host OS.
## Related Tools/Techniques
- **Evilginx2 / Muraena**: Common frameworks used for AiTM phishing.
- **Stealer Malware**: Used to harvest cookies and browser profiles from the disk (e.g., RedLine, Racoon).
- **Search Engine Poisoning (SEO Hijacking)**: Used to lure victims to AiTM pages.