{"id":12062,"date":"2024-09-09T08:35:30","date_gmt":"2024-09-09T15:35:30","guid":{"rendered":"https:\/\/legacy.gosecure.ai\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/"},"modified":"2024-09-23T06:53:02","modified_gmt":"2024-09-23T13:53:02","slug":"hated-by-many-loved-by-hackers-edges-role-in-staying-undetected","status":"publish","type":"post","link":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/","title":{"rendered":"Hated by Many, Loved by Hackers: Edge&rsquo;s Role in Staying Undetected"},"content":{"rendered":"<p><img class=\"size-medium wp-image-12040 alignright\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/Edge1-300x300.jpg\" alt=\"\" width=\"300\" height=\"300\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/Edge1-300x300.jpg 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/Edge1-150x150.jpg 150w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/Edge1-480x482.jpg 480w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/Edge1.jpg 581w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>A staggering <a href=\"https:\/\/data.lib.vt.edu\/articles\/dataset\/_b_Cross-Sectional_Survey_of_Cybercriminology_-_September_2021_b_\/24808245\/1\">87% of people believe that malicious hackers possess exceptional computer skills<\/a>. One might assume they would predominantly use anonymity networks like Tor to mask their true identities. However, our study reveals that attackers share the same browser preferences as the general population and choose it in relation to their malicious intentions. In this blog, we explore the nuances of browser choices made by attackers who have compromised a system.<\/p>\n<p>What if I told you that it\u2019s possible to spy on malicious hackers and gather information about their actions without them knowing? In fact, this can be done thanks to <a href=\"https:\/\/github.com\/GoSecure\/pyrdp\">PyRDP<\/a>, an open-source tool developed by GoSecure\u2019s research team. This opportunity to observe attackers provides many interesting avenues for research that has the potential to contribute greatly to the field of cybersecurity. In this blog post we will explore attackers\u2019 behavior related to their preferred browser.<\/p>\n<h2>Browser preferences in previous studies<\/h2>\n<p>We all have our personal favorite browser, and <a href=\"https:\/\/plg.uwaterloo.ca\/~migod\/papers\/2006\/jss-browserRefArch.pdf\">that choice mainly depends on our preferences and needs<\/a>. In other words, the features of a browser impact our choice when deciding which one we will use.<\/p>\n<p>Researchers explored the five most popular web browsers (Chrome, Firefox, Internet Explorer, Opera, and Safari) and they conducted a pre- and post-test experimental study in which the 105 participants had to test the different features. Prior to the tests, the majority of students used Chrome. After the tests, while Chrome remained the most used browser, Firefox and Opera saw slight increases in usage. Meanwhile, Internet Explorer and Safari maintained consistent usage levels before and after the tasks. It is worthy to mention that participants notably considered browser responsiveness when making their choices of preferred browser.<\/p>\n<p>Another <a href=\"https:\/\/par.nsf.gov\/servlets\/purl\/10344954\">study<\/a> focused on security and privacy complications specifically for Opera, Chrome, Safari, Firefox, Internet Explorer, and Microsoft Edge. They found that Chrome and Safari are the two most used browsers. However, despite its widespread usage, Chrome also emerges as the most frequently targeted browser for hacking. Conversely, Firefox is touted as the most secure and reliable alternative. Users transitioning from Chrome to Firefox may experience positive changes in privacy.<\/p>\n<p>The browsers mentioned above are tailored for users accessing what\u2019s known as the surface web, consisting of indexed content accessible through traditional browsers. However, <a href=\"https:\/\/sgp.fas.org\/crs\/misc\/R44101.pdf\">two other layers of the internet exists<\/a>: the deep web, containing both indexed and non-indexed content, and the dark web, housing intentionally concealed content accessible only through specialized browsers like <a href=\"https:\/\/www.torproject.org\/\">The Onion Router (Tor).<\/a><\/p>\n<p>We know that cybercriminals find it advantageous to use Tor due to its privacy features, and that the most widely used browser among the general population, Chrome, is the most targeted browser for hacking attempts. But there appears to be a notable gap in the literature regarding knowledge about web browsers and their usage by cybercriminals. While the previous studies mentioned shed light on browser preferences among the general population, we wanted to explore the preferences among cybercriminals. No study examines browser preferences among cybercriminals or seeks to understand why certain browsers are favored over others by this group. To fill the gap in the literature, this research aims to primarily describe the behaviors of cybercriminals regarding their preferred browser.<\/p>\n<h2>Which browser do attackers use?<\/h2>\n<p>The research team deployed high interaction honeypots and collected the data using PyRDP, a powerful tool designed to intercept and analyze attacks on remote desktop connections by attackers. <a href=\"https:\/\/apps.dtic.mil\/sti\/trecms\/pdf\/AD1201693.pdf\">It includes various applications<\/a>, notably those that can capture video recordings of attacks and log the attacker\u2019s mouse movements. By analyzing 454 video captures that have been recorded between January 2021 and June 2023, we codified the characteristics and behaviors of each session in a comprehensive database. In the analysis of this research project, an emphasis has been put on analyzing the choice of browser of the attackers.<\/p>\n<p><em> <img class=\"aligncenter wp-image-12052 size-large\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/SophieFig1-1024x524.png\" alt=\"\" width=\"1024\" height=\"524\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-1024x524.png 1024w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-300x154.png 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-768x393.png 768w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-1536x787.png 1536w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-2048x1049.png 2048w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-1080x553.png 1080w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-1280x656.png 1280w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-980x502.png 980w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieFig1-480x246.png 480w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/em><\/p>\n<p style=\"text-align: center;\"><em>Figure 1. Frequency of preferred browser (N = 454)<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>Figure 1 shows that in the majority of cases (74.7%), attackers do not download or use any browser. However, among the 115 sessions where a browser choice was evident, Chrome was the most preferred (15.9%). It was followed by the default browser that is already installed on the session (that is Explorer or Edge). Two other browsers were observed: Firefox (2.9%), and Netbox (only one instance &#8211; 0.2%).<\/p>\n<p>Despite being unaware of their surveillance, we can see that no attacker decided to download Tor, and two primary hypotheses can explain this behavior.<\/p>\n<ol>\n<li>Existing Anonymity Measures:<\/li>\n<\/ol>\n<p>Malicious hackers might not feel the need to use Tor because they already mask their identities through the systems they use to gain access. By employing multiple computers as relays, they can effectively hide their identity, making Tor unnecessary.<\/p>\n<ol start=\"2\">\n<li>Tor Being Potentially Blocked:<\/li>\n<\/ol>\n<p>Tor is frequently blocked by IT administrators. If malicious hackers were to download Tor, it could trigger alerts and lead to detection of unauthorized activity. Consequently, the risk of being caught increases if they opt for this option.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<h2>What is the relationship between preferred browser and attackers\u2019 activities?<\/h2>\n<p>One of the objectives of this research project was to see if we could do a portrait for attackers depending on their preferred browser. We therefore observe the actions performed by the attackers during their session on our system and see if they could be predicted by their preferred browser. We tested 31 different types of actions but most of them were not statistically significant. In the tables below, we present the variables that were interesting and significant.<\/p>\n<p>Certain actions performed by attackers, such as testing the internet power of our system, are not adequately predicted by the choice of browser. As observed in Graph 1, the strength of the relationship is similar for all browsers, leading to no conclusive insights from this variable.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><em>Graph 1. Chi-Square Test for Attackers Testing Internet Power of Our System<br \/>\n<img class=\"alignnone wp-image-12050 size-large\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/SophieGraph1-1024x597.png\" alt=\"\" width=\"1024\" height=\"597\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1-1024x597.png 1024w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1-300x175.png 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1-768x448.png 768w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1-1536x896.png 1536w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1-1080x630.png 1080w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1-1280x747.png 1280w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1-980x572.png 980w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1-480x280.png 480w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph1.png 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/em><em>p &lt; 0,001<\/em><\/p>\n<p>Other variables showed more promising results. For example, using the default browser is a predictor for the action of checking the IP, as shown in Graph 2. It is well understood that that <a href=\"https:\/\/research.ijcaonline.org\/volume63\/number6\/pxc3885202.pdf\">the reconnaissance phase performed by attackers is mainly passive<\/a> and aims to limit system interactions to avoid detection. Consequently, using the system&rsquo;s default browser minimizes detection risks while efficiently gathering system information.<\/p>\n<p><em>\u00a0<\/em><\/p>\n<p style=\"text-align: center;\"><em>Graph 2. Chi-Square Test for Attackers Checking the IP of Our System<br \/>\n<img class=\"alignnone wp-image-12048 size-large\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/SophieGraph2-1024x597.png\" alt=\"\" width=\"1024\" height=\"597\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2-1024x597.png 1024w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2-300x175.png 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2-768x448.png 768w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2-1536x896.png 1536w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2-1080x630.png 1080w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2-1280x747.png 1280w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2-980x572.png 980w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2-480x280.png 480w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph2.png 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/em><em>p &lt; 0,001<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>Graph 3 reveals that using Chrome is a predictor for attackers downloading tools during their session on our system. This behavior indicates a different approach compared to attackers using the default browser. Those using the default browser appear to focus more on reconnaissance, whereas Chrome users are likely present for a longer duration and engage in a broader range of actions. This result align with the behavior classifications of attackers previously hypothesized in a previous <a href=\"https:\/\/legacy.gosecure.ai\/blog\/2023\/08\/09\/how-unparalleled-rdp-monitoring-reveal-attackers-tradecraft\/\">blog post<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><em>Graph 3. Chi-Square Test for Attackers Downloading Tools to perform actions<br \/>\n<img class=\"alignnone wp-image-12046 size-large\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/SophieGraph3-1024x597.png\" alt=\"\" width=\"1024\" height=\"597\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3-1024x597.png 1024w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3-300x175.png 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3-768x448.png 768w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3-1536x896.png 1536w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3-1080x630.png 1080w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3-1280x747.png 1280w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3-980x572.png 980w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3-480x280.png 480w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph3.png 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/em><em>\u00a0<\/em><em>p &lt; 0,001<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>Lastly, Graph 4 presents an interesting observation regarding the skills of attackers. Users of Chrome and the default browser tend to fail at completing certain actions, whereas Firefox and Netbox users do not exhibit the same issue. This suggests a potential difference in skill levels among attackers using different browsers, warranting further investigation into the skills of these attackers.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><em>Graph 4. Chi-Square Test for Attackers Failing to complete their action<br \/>\n<img class=\"alignnone wp-image-12044 size-large\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/SophieGraph4-1024x597.png\" alt=\"\" width=\"1024\" height=\"597\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4-1024x597.png 1024w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4-300x175.png 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4-768x448.png 768w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4-1536x896.png 1536w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4-1080x630.png 1080w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4-1280x747.png 1280w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4-980x572.png 980w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4-480x280.png 480w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/SophieGraph4.png 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/> <\/em><em>* = p &lt; 0,001<\/em><\/p>\n<h2>Does the preferred browser predict the type of tools attackers use?<\/h2>\n<p>Our comprehensive analysis of the types of tools used by attackers and their preferred browsers indicates that the choice of browser does not markedly influence the types of tools employed (e.g. monetizing; brute-forcing tools; etc.). However, several nuanced observations warrant attention. Notably, Netbox exhibits a stronger relationship with the use of monetization tools than other browsers. It is important to point out Netbox&rsquo;s capability to generate cryptocurrency through web navigation. The use of this browser already underscores a financial motivation among its users.<\/p>\n<p>Additionally, although the relationship is only marginally significant and the strength of the correlation is weak, Firefox also appears to predict, to some extent, the use of monetization tools when compared to other browsers.<\/p>\n<p>In summary, while the overall impact of browser choice on the selection of attack tools is limited, the specific associations observed with Netbox and Firefox highlight intriguing patterns that merit further investigation into the financial motivations and operational methodologies of attackers.<\/p>\n<h2>Conclusion<\/h2>\n<p>The primary objective of this study was to describe the browser preferences of malicious hackers. The findings reveal two significant insights. Firstly, attackers do not use the Tor browser. The context of the study led to two possible explanation: 1) Attackers might consider that their identities are already protected by the systems they infiltrate, and 2) Attackers wants to avoid the risk of detection by IT administrators associated with downloading Tor. The second insight is that attackers\u2019 choice of browser is related to their overall strategy rather than only their preferences. If they are doing reconnaissance, they typically use the default browser, Internet Explorer, but prefer Chrome when performing other activities, reflecting the preferences observed in non-criminal population.<\/p>\n<p>This study fills a notable gap in the literature, as no prior research had evaluated malicious hackers\u2019 browser preferences and their impact on their activities. The results allow for generalizing conclusions from the general population\u2019s browser preferences to malicious hackers, confirming that browser choice is dependent on user preferences and needs, consistent with existing literature.<\/p>\n<p>Author: Sophie Marchand<\/p>\n<div id=\"left-area\">\n<article id=\"post-11959\" class=\"et_pb_post post-11959 post type-post status-publish format-standard hentry category-hackers category-proxy category-uncategorized tag-assessment tag-cybersecurity-statistics tag-hackers tag-honeypots tag-proxy tag-pyrdp\">\n<div class=\"entry-content\">\n<p><em>We would like to thank Andr\u00e9anne Bergeron for the supervision of this research project and for further writing and reviewing of this blogpost.\u00a0<\/em><\/p>\n<\/div>\n<\/article>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p><img class=\"size-medium wp-image-12040 alignright\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/Edge1-300x300.jpg\" alt=\"\" width=\"300\" height=\"300\" \/>A staggering <a href=\"https:\/\/data.lib.vt.edu\/articles\/dataset\/_b_Cross-Sectional_Survey_of_Cybercriminology_-_September_2021_b_\/24808245\/1\">87% of people believe that malicious hackers possess exceptional computer skills<\/a>. One might assume they would predominantly use anonymity networks like Tor to mask their true identities. However, our study reveals that attackers share the same browser preferences as the general population and choose it in relation to their malicious intentions. In this blog, we explore the nuances of browser choices made by attackers who have compromised a system.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[556],"tags":[557,520,464],"class_list":["post-12062","post","type-post","status-publish","format-standard","hentry","category-cybersecurity-fr","tag-browser-fr","tag-cybersecurity-fr","tag-rdp-fr"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.0 (Yoast SEO v23.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Hated by Many, Loved by Hackers: Edge&#039;s Role in Staying Undetected - GoSecure<\/title>\n<meta name=\"description\" content=\"Attackers share the same browser preferences as the general population and choose it in relation to their malicious intentions. In this blog, we explore the nuances of browser choices made by attackers who have compromised a system.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hated by Many, Loved by Hackers: Edge&#039;s Role in Staying Undetected\" \/>\n<meta property=\"og:description\" content=\"Attackers share the same browser preferences as the general population and choose it in relation to their malicious intentions. In this blog, we explore the nuances of browser choices made by attackers who have compromised a system.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/\" \/>\n<meta property=\"og:site_name\" content=\"GoSecure\" \/>\n<meta property=\"article:published_time\" content=\"2024-09-09T15:35:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-23T13:53:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/Edge1-300x300.jpg\" \/>\n<meta name=\"author\" content=\"GoSecure\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:site\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"GoSecure\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/\",\"name\":\"Hated by Many, Loved by Hackers: Edge's Role in Staying Undetected - GoSecure\",\"isPartOf\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/Edge1-300x300.jpg\",\"datePublished\":\"2024-09-09T15:35:30+00:00\",\"dateModified\":\"2024-09-23T13:53:02+00:00\",\"author\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\"},\"description\":\"Attackers share the same browser preferences as the general population and choose it in relation to their malicious intentions. In this blog, we explore the nuances of browser choices made by attackers who have compromised a system.\",\"breadcrumb\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#primaryimage\",\"url\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/Edge1-300x300.jpg\",\"contentUrl\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/Edge1-300x300.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/legacy.gosecure.ai\/fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hated by Many, Loved by Hackers: Edge&#8217;s Role in Staying Undetected\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/\",\"name\":\"GoSecure\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\",\"name\":\"GoSecure\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Hated by Many, Loved by Hackers: Edge's Role in Staying Undetected - GoSecure","description":"Attackers share the same browser preferences as the general population and choose it in relation to their malicious intentions. In this blog, we explore the nuances of browser choices made by attackers who have compromised a system.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/","og_locale":"fr_FR","og_type":"article","og_title":"Hated by Many, Loved by Hackers: Edge's Role in Staying Undetected","og_description":"Attackers share the same browser preferences as the general population and choose it in relation to their malicious intentions. In this blog, we explore the nuances of browser choices made by attackers who have compromised a system.","og_url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/","og_site_name":"GoSecure","article_published_time":"2024-09-09T15:35:30+00:00","article_modified_time":"2024-09-23T13:53:02+00:00","og_image":[{"url":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/Edge1-300x300.jpg"}],"author":"GoSecure","twitter_card":"summary_large_image","twitter_creator":"@GoSecure_Inc","twitter_site":"@GoSecure_Inc","twitter_misc":{"\u00c9crit par":"GoSecure","Dur\u00e9e de lecture estim\u00e9e":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/","url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/","name":"Hated by Many, Loved by Hackers: Edge's Role in Staying Undetected - GoSecure","isPartOf":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#primaryimage"},"image":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#primaryimage"},"thumbnailUrl":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/Edge1-300x300.jpg","datePublished":"2024-09-09T15:35:30+00:00","dateModified":"2024-09-23T13:53:02+00:00","author":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca"},"description":"Attackers share the same browser preferences as the general population and choose it in relation to their malicious intentions. In this blog, we explore the nuances of browser choices made by attackers who have compromised a system.","breadcrumb":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#primaryimage","url":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/Edge1-300x300.jpg","contentUrl":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/Edge1-300x300.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/09\/09\/hated-by-many-loved-by-hackers-edges-role-in-staying-undetected\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legacy.gosecure.ai\/fr\/"},{"@type":"ListItem","position":2,"name":"Hated by Many, Loved by Hackers: Edge&#8217;s Role in Staying Undetected"}]},{"@type":"WebSite","@id":"https:\/\/legacy.gosecure.ai\/fr\/#website","url":"https:\/\/legacy.gosecure.ai\/fr\/","name":"GoSecure","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca","name":"GoSecure"}]}},"_links":{"self":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/12062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/comments?post=12062"}],"version-history":[{"count":0,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/12062\/revisions"}],"wp:attachment":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/media?parent=12062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/categories?post=12062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/tags?post=12062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}