NEWS

The EDR Blind Spot: 3 Ways Browser Attacks Evade Endpoint Telemetry

AiTM phishing, malicious extensions, and clipboard-hijack attacks finish inside the browser, leaving little for endpoint detection tools to catch.

Dylan H.

News Desk

October 3, 2026
9 min read
The EDR Blind Spot: 3 Ways Browser Attacks Evade Endpoint Telemetry

Browser Sessions Are Becoming the Blind Spot in Endpoint Detection

Endpoint Detection and Response (EDR) tools are built to flag malicious processes, suspicious executables, and unusual host behavior — but a growing share of enterprise attacks never produce any of that. According to an analysis published by BleepingComputer on October 2, 2026, written by Andrius Buinovskis, VP of product strategy at network security vendor NordLayer, attackers are increasingly completing entire intrusions — credential theft, data exfiltration, even financial fraud — inside a legitimate browser session, where the activity looks like normal user behavior to an endpoint agent. NordLayer's Browser Security Report 2026, which reviewed 504 business applications, found browser access present across all of them, with 79% available exclusively through the browser — meaning the browser, not the operating system, is now the primary corporate access layer. The piece outlines three real-world attack patterns — adversary-in-the-middle phishing, malicious browser extensions, and clipboard-hijacking social engineering — that each complete without the new process, dropped file, or suspicious executable that EDR is designed to inspect.


Details

AttributeValue
Analysis publishedOctober 2, 2026 (BleepingComputer, sponsored/contributed piece)
AuthorAndrius Buinovskis, VP Product Strategy, NordLayer
Core findingBrowser-based attacks can complete without creating endpoint-visible artifacts
Techniques covered3 — AiTM phishing, malicious extensions, clipboard/social-engineering execution
Supporting dataNordLayer Browser Security Report 2026 — 504 apps reviewed, 79% browser-only
Cited incidentsStorm-2755 "Payroll Pirate" campaign; malicious AI-assistant Chrome extensions; TerminalFix ClickFix campaign; Salesloft Drift / UNC6395 OAuth abuse
Proposed mitigationLayered controls spanning browser, identity/SaaS, and endpoint

How Browser Attacks Slip Past EDR

EDR agents are tuned to host-level signals: new processes, registry changes, suspicious binaries, and anomalous parent-child process trees. All three techniques below avoid tripping those signals because the attacker's actions happen inside a browser process using standard browser behavior — rendering a page, running an extension API call, or relying on a human to paste and run a command themselves.

1. Adversary-in-the-Middle (AiTM) Phishing and Session Hijacking

The clearest example is Storm-2755, a financially motivated threat actor Microsoft's Detection and Response Team identified running "Payroll Pirate" attacks against Canadian employees. The campaign used malicious advertisements and search-engine manipulation to drive victims to spoofed Microsoft 365 login pages — one confirmed domain was bluegraintours[.]com — that acted as AiTM proxy servers, relaying the real authentication flow while capturing session cookies and OAuth tokens in transit. Because the proxy forwards traffic to the legitimate identity provider, it bypasses MFA that isn't phishing-resistant, and the victim ends up authenticated normally, with no malware ever touching their device.

Once inside, Storm-2755 searched the victim's inbox and intranet for terms like "payroll," "HR," "direct deposit," and "finance," then created inbox rules that silently filed away messages containing "direct deposit" or "bank" so the victim would never see HR's response to a fraudulent banking-change request. The actor either social-engineered HR directly or signed into Workday using the stolen session to redirect the employee's paycheck to an attacker-controlled account. None of this required dropping an executable — it was all authenticated, browser-mediated activity that looked identical to the employee's own session.

2. Compromised Browser Extensions

In March 2026, Microsoft reported on malicious Chromium extensions masquerading as AI assistant tools, installed roughly 900,000 times across more than 20,000 enterprise tenants. Two extensions — one posing as "Chat GPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI" (over 600,000 installs) and another as "AI Sidebar with DeepSeek, ChatGPT, Claude and more" (over 300,000 installs) — mimicked a legitimate AI sidebar product; one listing even carried Google's "Featured" badge, lending it unearned trust. Using only standard browser extension APIs, the extensions read page content, tracked visited URLs, and harvested full ChatGPT and DeepSeek conversation histories, exfiltrating the data to attacker-controlled infrastructure roughly every 30 minutes — a technique researchers later dubbed "Prompt Poaching."

From an EDR perspective, this activity runs inside the browser's own process space, uses sanctioned extension permissions, and communicates out over ordinary HTTPS. There is no new process to classify as malicious and no executable to scan — just a browser doing what browsers do, while quietly leaking proprietary code, internal workflows, and strategic conversations typed into an AI chat window.

3. Clipboard Hijacking and Social-Engineering Execution

The third pattern — exemplified by the TerminalFix campaign Microsoft disclosed on August 28, 2026 — gets a human to do the dangerous part voluntarily. Compromised websites display a fake Cloudflare Turnstile verification overlay, complete with animated spinners and a branded checkbox. Clicking it silently copies a malicious PowerShell command to the clipboard; the page then instructs the visitor to open Windows Terminal and paste it in to "complete verification." Unlike earlier ClickFix variants that targeted the Run dialog, directing victims to a full terminal makes it easier to execute longer, multi-stage scripts.

Once run, the command retrieves a ZIP archive containing a legitimate signed binary (LockScreenContentServer.exe) alongside a malicious DLL (dui70.dll) used for DLL sideloading, then pulls additional payloads hidden inside ordinary-looking PNG images using steganography. The chain establishes persistence via Registry Run keys and scheduled tasks, ultimately opening an encrypted reverse tunnel that gives the threat actor inbound access to the network. Critically, no vulnerability is exploited anywhere in this chain — every step uses legitimate Windows functionality the user triggered themselves, which is exactly why there is no patch for it and why EDR has to rely on post-execution behavioral detection rather than a clear malicious-file signature.

NordLayer's piece also points to the 2025 Salesloft Drift breach, where the group tracked as UNC6395 used stolen OAuth tokens tied to Drift integrations to make high-volume API calls against customers' Salesforce environments — another case where data theft happened entirely through authenticated, identity-layer access with no malware process for EDR to inspect.

Impact Assessment

Impact AreaDescription
Detection gapAll three techniques complete inside legitimate browser or identity workflows, generating none of the process-level artifacts EDR is tuned to flag
Financial lossStorm-2755's AiTM campaign redirected employee paychecks by manipulating Workday direct-deposit settings and confirmed at least one direct financial loss
Data exposureMalicious AI-assistant extensions harvested chat histories — potentially including proprietary code and strategic discussions — from roughly 900,000 installs across 20,000+ tenants
Follow-on accessTerminalFix's reverse tunnel grants persistent network access that researchers warn could enable lateral movement, credential theft, or ransomware deployment
Identity/SaaS abuseStolen OAuth tokens (as in the Salesloft Drift incident) allow high-volume data exfiltration via legitimate API calls, bypassing both EDR and basic anomaly thresholds

Recommendations

For Security Teams and SOC Analysts

  • Audit sign-in logs for AiTM indicators: error code 50199, anomalous session continuity, and unusual user-agent strings (such as Axios) associated with token-replay tooling.
  • Treat inbox-rule creation — especially rules filtering on "bank," "direct deposit," or "payroll" — as a high-priority detection signal, not routine mailbox hygiene.
  • Extend monitoring beyond the endpoint into identity and SaaS telemetry: OAuth grant activity, Workday/HRIS admin changes, and API call volume against platforms like Salesforce.
  • Investigate ClickFix-style incidents even when no malware signature fires; look for PowerShell or Terminal history showing pasted commands shortly after a browser-rendered "verification" prompt.

For IT Administrators

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn) rather than relying solely on push-based or OTP factors that AiTM proxies can relay.
  • Enforce centralized browser extension allow-lists; block installation of unvetted extensions, particularly those requesting broad host permissions or claiming AI-assistant functionality.
  • Apply clipboard and web-threat protection at the browser layer to interrupt ClickFix-style campaigns before a user can paste a malicious command into a terminal.
  • Revoke active session tokens and reset credentials immediately for any account suspected of AiTM compromise — stolen cookies remain valid until explicitly invalidated.

For End Users

  • Never paste "verification" commands into PowerShell, Windows Terminal, or the Run dialog, regardless of how convincing the CAPTCHA page looks — legitimate verification never asks for this.
  • Be skeptical of AI-assistant browser extensions, especially ones promising access to multiple paid chatbots for free; verify the publisher and read recent reviews before installing.
  • Double-check the URL bar before entering Microsoft 365 or other SSO credentials, particularly after clicking a search ad or sponsored result.
  • Report unexpected HR or payroll emails requesting direct-deposit changes through a verified channel rather than replying directly.

Key Takeaways

  1. EDR is built to catch host-level artifacts — new processes, dropped executables, registry persistence — and all three techniques described here largely avoid producing them.
  2. AiTM phishing (Storm-2755) steals session cookies and OAuth tokens in real time, bypassing non-phishing-resistant MFA and leaving attackers inside a fully authenticated browser session.
  3. Malicious browser extensions operate with standard API permissions, making data harvesting — in this case, nearly 900,000 installs exfiltrating AI chat histories — indistinguishable from normal extension activity to endpoint tools.
  4. ClickFix-style campaigns like TerminalFix exploit user trust rather than software vulnerabilities, so there is no patch to apply — defense depends on interrupting the clipboard-to-terminal chain before execution.
  5. NordLayer's Browser Security Report 2026 found 79% of 504 reviewed business applications are accessible only through the browser, underscoring why browser-layer controls are no longer optional.
  6. Closing the gap requires layered visibility across browser, identity/SaaS, and endpoint — no single control category sees the whole attack chain on its own.

Sources