If your incident response statistics from the last 18 months look anything like ours at Security Arsenal, a pattern jumps out: the majority of intrusion chains we're investigating never touch a traditional exploit. No kernel bug, no memory corruption, no EDR-bypassing loader dropped to disk in the classic sense. The initial access broker, the credential thief, and often the exfiltration channel all live inside a single browser session.
This tracks with the broader industry picture. Business applications — email, CRM, ERP, source code, finance consoles, cloud control planes — are consumed through the browser. Identity is brokered through the browser. Session tokens, OAuth grants, and SSO cookies all materialize in browser memory and on browser-controlled storage. From an attacker's cost-benefit perspective, why burn a zero-day when the user will hand you a valid session in exchange for a convincing CAPTCHA page?
A recent analysis from The Hacker News, Know Your Enemy: Browser-Based Attack Techniques in 2026, crystallizes what we've been seeing across engagements: breaches begin in the browser session, and increasingly the entire attack chain — initial access, credential harvest, persistence, and exfiltration — never leaves it. This post breaks down the six technique families our SOC and IR teams are treating as highest priority in 2026, and gives you the detections and hardening steps to fight back.
Technical Analysis: The Six Technique Families
None of these techniques depend on a single CVE — that's precisely the point. They abuse legitimate browser functionality, identity flows, and user trust. There is no patch for "the user ran a command." Defense has to be behavioral and architectural.
1. ClickFix-Style Social Engineering (Fake CAPTCHA / "Fix It" Lures)
The single fastest-growing initial access vector we've handled in 2025–2026. The victim lands on a compromised or malicious page showing a fake CAPTCHA, a fake "browser update," or a fake error message instructing them to press Win+R, paste a clipboard-loaded command, and hit Enter. The clipboard content — staged silently by JavaScript on the page — is typically a PowerShell or mshta one-liner that pulls second-stage malware (we most often see Lumma, StealC, and NetSupport RAT follow-on payloads).
Defender's view of the chain: browser process → user manually spawns powershell.exe, mshta.exe, or wscript.exe via the Run dialog or File Explorer address bar → encoded/download-cradle command executes → payload stages from a remote host. The critical forensic artifact is that the malicious child process is not a child of the browser — the user launched it — which defeats naive parent-child detections. You need to key on the command-line content and the execution context instead.
2. Adversary-in-the-Middle (AiTM) Phishing and Session Token Theft
AiTM kits (Evilginx-class reverse proxies and their commercial successors) sit transparently between the victim and the real identity provider. The victim completes genuine MFA — push, OTP, even some FIDO-adjacent flows get proxied in real time — and the attacker walks away with the authenticated session cookie. MFA passed; the session is compromised anyway.
Defender's view: the tell is rarely in the authentication itself. It's in what follows — a session token replayed from an impossible-travel geography, a different ASN, a datacenter IP, or a device fingerprint that doesn't match the enrollment record. Token theft is an identity-layer detection problem, not an endpoint one.
3. Malicious and Compromised Browser Extensions
Extensions hold cookies, webRequest, and content-script permissions that amount to full read/write access to every page the user touches — including your IdP login page and your SaaS consoles. We see two variants: extensions published malicious from day one, and legitimate extensions acquired or update-hijacked to push credential-harvesting code to an installed base. Several 2025–2026 campaigns pushed infostealer logic through auto-update to hundreds of thousands of Chrome and Edge users simultaneously.
Defender's view: extensions are unmanaged code executing with browser-level privilege. If you cannot enumerate every extension installed across your fleet right now, you have an unpatched software inventory problem worse than your OS patching gap.
4. HTML Smuggling and Browser-Native Payload Assembly
Rather than delivering an executable that email gateways and secure web gateways can inspect, attackers deliver an HTML file (or a page) that assembles the payload client-side with JavaScript — Blob objects, atob() decoding, navigator.msSaveBlob/URL.createObjectURL — and triggers the download locally. The malicious binary never crosses the wire as a binary, so perimeter inspection sees benign HTML and JavaScript.
Defender's view: watch for browsers writing executable content (.exe, .dll, .js, .lnk, .iso) into user-writable paths immediately following an HTML file open, and for archive/ISO mounts followed by execution. Mark-of-the-Web handling and SmartScreen reputation are your perimeter here.
5. OAuth Consent Phishing and App Grant Abuse
Instead of stealing a password, the attacker gets the user to consent to a malicious third-party OAuth application with scopes like Mail.Read, offline_access, or Files.Read.All. The grant survives password resets, survives MFA, and gives the attacker API-level access from infrastructure that looks like legitimate cloud-to-cloud traffic. Persistence without malware.
Defender's view: audit consent grants continuously, alert on newly registered apps requesting high-value scopes, and — most importantly — configure user consent policies so end users cannot approve broad scopes without admin review.
6. Browser-in-the-Browser (BitB) and Credential UI Spoofing
BitB renders a fake SSO popup — pixel-accurate, with a legitimate-looking URL bar — inside a page the attacker controls. Variants now abuse legitimate identity-provider-hosted content, progressive web app windows without chrome/URL display, and fullscreen API tricks to make the fake window indistinguishable from a real one. Combined with AiTM backend logic, the harvest is complete.
Defender's view: the reliable defense is phishing-resistant authentication — FIDO2/WebAuthn passkeys bound to origin. A spoofed window on the wrong origin cannot complete a WebAuthn ceremony. Conditional Access with token protection and compliant-device requirements raises the bar further.
Exploitation Status
These are not theoretical. ClickFix-style lures have been confirmed in mass campaigns and targeted intrusions throughout 2025 and into 2026; AiTM session theft is a standard offering in phishing-as-a-service kits; malicious extension campaigns have hit Chrome Web Store and Edge Add-ons users at scale. Treat all six as actively exploited in the wild.
Detection & Response
The following rules target the highest-signal, lowest-noise observables. Deploy the Sigma rules against your endpoint telemetry, the KQL against Defender/Sentinel, and the VQL for fleet-wide hunting.
---
title: ClickFix-Style User-Launched Script Interpreter with Download Cradle
id: 3f9c1a72-8b2d-4e51-9c47-6a2d8f10b3e5
status: experimental
description: Detects script interpreters launched with encoded or download-cradle command lines characteristic of ClickFix fake CAPTCHA lures, where the user is tricked into pasting a command into the Run dialog. Keys on command content rather than parent process, since the user launches the process directly.
references:
- https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html
- https://attack.mitre.org/techniques/T1204/
- https://attack.mitre.org/techniques/T1059/001/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.execution
- attack.initial_access
- attack.t1204
- attack.t1059.001
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\mshta.exe'
- '\wscript.exe'
- '\cscript.exe'
selection_cli:
CommandLine|contains:
- ' -enc '
- ' -e '
- 'FromBase64String'
- 'IEX'
- 'Invoke-Expression'
- 'Invoke-WebRequest'
- 'wget '
- 'curl '
- 'Start-BitsTransfer'
- 'hidden'
filter_legit:
CommandLine|contains:
- 'Invoke-WebRequest -Uri https://aka.ms/'
- 'Microsoft.PowerShell_profile.ps1'
condition: selection_img and selection_cli and not filter_legit
falsepositives:
- Software deployment tooling and admin scripts using encoded commands; tune the filter to your deployment tooling
level: high
---
title: Browser Process Writing Executable Content to User Directories
id: 8d2e5b91-4c7a-4f38-a156-9e3c7d02f841
status: experimental
description: Detects browser processes writing executables, scripts, or disk images to user-writable locations, consistent with HTML smuggling payload assembly and malicious download staging.
references:
- https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html
- https://attack.mitre.org/techniques/T1027/006/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.defense_evasion
- attack.t1027.006
- attack.t1204.002
logsource:
category: file_event
product: windows
detection:
selection_browser:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\firefox.exe'
- '\brave.exe'
selection_target:
TargetFilename|endswith:
- '.exe'
- '.dll'
- '.js'
- '.jse'
- '.vbs'
- '.hta'
- '.lnk'
- '.iso'
- '.bat'
- '.ps1'
selection_path:
TargetFilename|contains:
- '\AppData\Local\Temp\'
- '\Downloads\'
- '\AppData\Roaming\'
filter_ext:
TargetFilename|contains:
- '\AppData\Local\Google\Chrome\'
- '\AppData\Local\Microsoft\Edge\'
- '\AppData\Local\Mozilla\'
condition: selection_browser and selection_target and selection_path and not filter_ext
falsepositives:
- Legitimate software downloads by users; pair with execution correlation before escalating
level: medium
---
title: Suspicious Browser Extension Install via Preferences Tampering
id: 5a71c3e6-2d94-4b08-8f23-1c9a6e54d7b2
status: experimental
description: Detects non-browser processes modifying Chrome or Edge extension directories or Secure Preferences, indicative of forced extension installation or extension tampering by malware.
references:
- https://thehackernews.com/2026/09/know-your-enemy-browser-based-attack.html
- https://attack.mitre.org/techniques/T1176/
author: Security Arsenal
date: 2026/09/15
tags:
- attack.persistence
- attack.t1176
logsource:
category: file_event
product: windows
detection:
selection_path:
TargetFilename|contains:
- '\Google\Chrome\User Data\'
- '\Microsoft\Edge\User Data\'
selection_file:
TargetFilename|endswith:
- '\Secure Preferences'
- '\Preferences'
- '\manifest.json'
filter_browsers:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
condition: selection_path and selection_file and not filter_browsers
falsepositives:
- Enterprise extension management tooling (GPO-driven deployment is registry-based, not direct file writes); backup/restore utilities
level: high
// Hunt: ClickFix-style user-launched script interpreters with download cradles
// and follow-on network connections, plus browser-written executables.
// Tables: DeviceProcessEvents, DeviceFileEvents, DeviceNetworkEvents (Defender for Endpoint / Sentinel)
let lookback = 7d;
let suspiciousCli = dynamic(["-enc", "FromBase64String", "IEX", "Invoke-Expression",
"Invoke-WebRequest", "Start-BitsTransfer", "mshta http", "curl ", "wget "]);
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where FileName in~ ("powershell.exe", "pwsh.exe", "mshta.exe", "wscript.exe", "cscript.exe", "rundll32.exe")
| where ProcessCommandLine has_any (suspiciousCli)
// User-launched (Run dialog/Explorer) rather than spawned by browser or Office
| where InitiatingProcessFileName in~ ("explorer.exe", "svchost.exe", "cmd.exe")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine,
InitiatingProcessFileName, InitiatingProcessCommandLine, ProcessId, SHA256
| join kind=leftouter (
DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| project ProcessId, DeviceName, RemoteUrl, RemoteIP, RemotePort, ActionType
) on ProcessId, DeviceName
| project-away ProcessId1, DeviceName1
| order by TimeGenerated desc;
// Companion hunt: browsers dropping executable/script content into user paths
DeviceFileEvents
| where TimeGenerated > ago(lookback)
| where InitiatingProcessFileName in~ ("chrome.exe", "msedge.exe", "firefox.exe", "brave.exe")
| where FolderPath has_any ("\\Downloads\\", "\\AppData\\Local\\Temp\\", "\\AppData\\Roaming\\")
| where FileName endswith_any (".exe", ".dll", ".js", ".hta", ".lnk", ".iso", ".bat", ".ps1")
| where FolderPath !has_any ("\\Google\\Chrome\\", "\\Microsoft\\Edge\\", "\\Mozilla\\")
| join kind=leftouter (
DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| project DeviceName, FileName, ProcessCommandLine, TimeGenerated
) on DeviceName, FileName
| project TimeGenerated, DeviceName, FolderPath, FileName, SHA256,
InitiatingProcessFileName, ProcessCommandLine
| order by TimeGenerated desc;
-- Artifact: Browser-Based Attack Surface Hunt
-- Enumerates installed browser extensions (Chrome/Edge), unsigned or non-system
-- script interpreters with suspicious command lines, and browser-established
-- network connections to uncommon destinations.
LET extensions = SELECT
FullPath AS ExtensionManifest,
B.Name AS Browser,
basename(path=dirname(path=FullPath)) AS ExtensionID
FROM glob(
globs=[
'C:/Users/*/AppData/Local/Google/Chrome/User Data/*/Extensions/*/*/manifest.json',
'C:/Users/*/AppData/Local/Microsoft/Edge/User Data/*/Extensions/*/*/manifest.json'
])
LET Browser = parse_string_with_regex(
string=ExtensionManifest,
regex='(?P<b>Chrome|Edge)').b
LET suspicious_procs = SELECT
Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)powershell|pwsh|mshta|wscript|cscript'
AND CommandLine =~ '(?i)(-enc|FromBase64String|IEX|Invoke-Expression|Invoke-WebRequest|Start-BitsTransfer|http)'
LET browser_conns = SELECT
Pid, Name, Raddr AS RemoteAddress, Rport AS RemotePort, Status
FROM netstat()
WHERE Name =~ '(?i)chrome|msedge|firefox'
AND Status =~ 'ESTAB'
AND Rport =~ '^(80|443)$'
AND Raddr !~ '^(10\.|172\.(1[6-9]|2[0-9]|3[01])\.|192\.168\.|127\.)'
SELECT * FROM extensions
UNION ALL
SELECT NULL, NULL, NULL, * FROM suspicious_procs
# Browser-Based Attack Hardening & Audit Script
# Run elevated. Audits extensions, applies ClickFix mitigations, and checks MOTW handling.
$report = @()
# 1. Enumerate all installed Chrome/Edge extensions across user profiles
Write-Host "[+] Enumerating browser extensions..." -ForegroundColor Cyan
$extPaths = @(
"$env:LOCALAPPDATA\Google\Chrome\User Data\*\Extensions\*\*\manifest.json",
"$env:LOCALAPPDATA\Microsoft\Edge\User Data\*\Extensions\*\*\manifest.json",
"C:\Users\*\AppData\Local\Google\Chrome\User Data\*\Extensions\*\*\manifest.json",
"C:\Users\*\AppData\Local\Microsoft\Edge\User Data\*\Extensions\*\*\manifest.json"
)
foreach ($p in $extPaths) {
Get-ChildItem -Path $p -ErrorAction SilentlyContinue | ForEach-Object {
try {
$m = Get-Content $_.FullName -Raw | ConvertFrom-Json
$perms = ($m.permissions + $m.host_permissions) -join ","
$risky = $perms -match "cookies|webRequest|<all_urls>|tabs|clipboardRead"
$report += [PSCustomObject]@{
Extension = ($_.FullName -split '\\')[-3]
Path = $_.FullName
RiskyPerms = $risky
Permissions = $perms
}
} catch {}
}
}
$report | Where-Object RiskyPerms | Format-Table -AutoSize
$report | Export-Csv "$env:TEMP\extension-audit.csv" -NoTypeInformation
Write-Host "[+] Full audit written to $env:TEMP\extension-audit.csv" -ForegroundColor Green
# 2. Enforce extension allowlisting via policy (Chrome + Edge)
# Replace the example IDs with your approved extension list.
$chromeKey = "HKLM:\SOFTWARE\Policies\Google\Chrome\ExtensionInstallAllowlist"
$edgeKey = "HKLM:\SOFTWARE\Policies\Microsoft\Edge\ExtensionInstallAllowlist"
$approved = @("ghbmnnjooekpmoecnnnilnnbdlolhkhi") # example: Google Docs Offline
foreach ($key in @($chromeKey, $edgeKey)) {
New-Item -Path $key -Force | Out-Null
$i = 1
foreach ($id in $approved) {
Set-ItemProperty -Path $key -Name $i -Value $id
$i++
}
# Block all extensions not on the allowlist
$blockKey = $key -replace 'ExtensionInstallAllowlist','ExtensionInstallBlocklist'
New-Item -Path $blockKey -Force | Out-Null
Set-ItemProperty -Path $blockKey -Name "1" -Value "*"
}
Write-Host "[+] Extension allowlist/blocklist policy applied (Chrome + Edge)" -ForegroundColor Green
# 3. ClickFix mitigation: block Run dialog + enforce MOTW zone checking
$runKey = "HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer"
New-Item -Path $runKey -Force | Out-Null
Set-ItemProperty -Path $runKey -Name "NoRun" -Value 1 -Type DWord
Write-Host "[+] Run dialog disabled for current user (ClickFix kill-chain break)" -ForegroundColor Green
$zoneKey = "HKLM:\SOFTWARE\Policies\Microsoft\Windows\Attachments"
New-Item -Path $zoneKey -Force | Out-Null
Set-ItemProperty -Path $zoneKey -Name "SaveZoneInformation" -Value 2 -Type DWord
Write-Host "[+] Mark-of-the-Web preservation enforced for downloaded files" -ForegroundColor Green
# 4. Verify PowerShell Script Block Logging is enabled (for post-ClickFix forensics)
$sbl = Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" -ErrorAction SilentlyContinue
if (-not $sbl -or $sbl.EnableScriptBlockLogging -ne 1) {
New-Item "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" -Force | Out-Null
Set-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging" -Name "EnableScriptBlockLogging" -Value 1
Write-Host "[+] PowerShell Script Block Logging enabled" -ForegroundColor Green
} else {
Write-Host "[=] Script Block Logging already enabled" -ForegroundColor Yellow
}
Write-Host "`n[+] Done. Review extension-audit.csv and triage entries with cookies/webRequest/<all_urls> permissions." -ForegroundColor Cyan
Remediation and Hardening: The 2026 Browser Defense Baseline
1. Kill the ClickFix kill chain. Disable the Run dialog for standard users via GPO (NoRun), enable PowerShell Script Block Logging and Constrained Language Mode where feasible, and train users specifically on the "paste this command to verify you're human" lure — generic phishing training does not cover this pattern. In our tabletop exercises, targeted ClickFix awareness cuts successful simulation rates faster than any other single control.
2. Move to phishing-resistant authentication. FIDO2 passkeys and certificate-based authentication are origin-bound — AiTM proxies and BitB windows cannot relay them. For Microsoft Entra ID environments, require compliant-device Conditional Access policies and enable token protection so stolen session cookies are cryptographically bound to the issuing device and useless elsewhere.
3. Govern extensions like software. Deploy ExtensionInstallAllowlist/ExtensionInstallBlocklist (Chrome/Edge GPO) or Firefox policy equivalents. Audit the existing installed base for extensions holding cookies, webRequest, or <all_urls> permissions — the audit script above gives you the inventory in minutes.
4. Constrain OAuth consent. Set Entra ID user consent to "do not allow" or admin-consent workflow for anything beyond low-risk scopes. Alert on new service principal consent grants requesting Mail.Read, Files.Read.All, or offline_access. Review existing grants quarterly — consent phishing persistence survives every password reset.
5. Detect token replay, not just logon. Build impossible-travel and ASN-change analytics on session establishment, not authentication events. Alert when a session validated minutes ago from a corporate egress IP suddenly appears from a datacenter or residential-proxy ASN.
6. Preserve and enforce Mark-of-the-Web. Ensure SmartScreen/Smart App Control is enabled, MOTW is not stripped by your proxy or file-transfer tooling, and ISO/IMG mounting followed by execution generates alerts.
7. Centralize browser telemetry. Browser history, download events, and extension inventory should flow into your SIEM alongside EDR process telemetry. The attack chain lives in the browser — if your visibility ends at the process table, you're investigating half the intrusion.
The perimeter didn't disappear; it moved into the tab bar. Security teams that instrument the browser session, bind identity to hardware, and treat extensions as managed code will catch these intrusions at initial access. Teams still waiting for a dropped executable will keep reading about themselves in breach disclosures.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.