logo

Browsers’ cache smuggling

ID: 0b0de784-8eb3-50ee-a666-0f35d7e8a799

STIX ID: report--0b0de784-8eb3-50ee-a666-0f35d7e8a799

Feed Name: SensePost Blog

Threat Score
70/100

Date Published: 2023-07-10

Date Updated: 2026-04-30

...
...

This report documents a technique termed "browser cache smuggling" in which an attacker coerces a browser to cache malicious DLL/EXE files (by overriding MIME types and adding identifying HTTP headers), then social engineers a user to run benign-looking PowerShell or batch commands that locate and execute or relocate the cached payload (including DLL side-loading via OneDrive); the write-up includes Nginx configuration examples, msfvenom payload creation, PowerShell extraction/run oneliners for Firefox and Chrome, and observations about Defender not scanning cached files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.