Skip to content

BROWSER DECOY · EARLY ACCESS

Stolen sessions skip passwords.
This one fires when used.

Infostealer malware and hostile extensions copy the cookies that keep you signed in, then replay them from another machine. No password or two-step code needed. The Vantuz Browser Decoy keeps one fake session in Chrome or Edge, next to the real ones. If anyone uses it, Vantuz alerts you.

Illustrative replay · sample data
  1. 01A decoy sessionThe extension keeps one fake login session in the browser, next to the real ones.
  2. 02The jar is copiedInfostealer malware copies every session in the browser, the decoy included.
  3. 03Replayed, answered 404The attacker replays them. The decoy domain answers with a plain 404, so they learn nothing.
  4. 04You knowVantuz opens an incident, scores it High and emails you plain next steps, starting with a quick check with the person.

HOW IT WORKS

Three steps. Then it waits.

Nothing changes for the person using the browser. The decoy sits quietly next to their real sessions until someone tries to use it.

  1. 01

    Create a code, or push a policy

    For one browser, an owner or admin creates an activation code in Vantuz and the person pastes it into the extension. The code works once, for 24 hours. For a fleet, IT pushes a policy through Google Admin or Microsoft Intune.

  2. 02

    The extension keeps a decoy session

    The Vantuz Browser Decoy holds one synthetic login session on a decoy domain Vantuz controls, and renews it every 6 hours. Your real sessions are never touched.

  3. 03

    A replay opens an incident

    When anyone replays the decoy session, the decoy domain answers with an ordinary 404. Vantuz opens an incident, emails you and lays out what to do first.

WHAT IT CATCHES

Anything that copies the browser's cookies and then uses them.

A copied session skips the password and the two-step code. The decoy does not care which tool did the copying: it fires when the copy is used.

Infostealer malware

Malware that copies the browser's saved sessions and sends them to whoever runs it.

Families like Lumma, RedLine and Vidar

Remote access tools

Anyone who gets onto the computer or into the browser profile and takes its cookies.

Remote access trojans, copied profiles

Malicious extensions

Browser add-ons that turn hostile, or were built to harvest cookies from the browser they live in.

Fake or hijacked add-ons

Pass-the-cookie

Anyone replaying a copied session from their own machine, whatever tool did the copying.

MITRE ATT&CK T1550.004

WHAT IT NEVER DOES

An extension that asks for little and sees less.

Any company should ask what an extension can see. This one can reach two addresses: the Vantuz control API and the decoy domain. Chrome only lets an extension touch cookies on the sites it can reach, so your real sessions, tabs and browsing stay out of its sight.

What it asks for3 permissions · 2 addresses
cookiesTo keep its one decoy cookie on the decoy domain
storageTo keep its own settings and state
alarmsTo renew the decoy session every 6 hours
Access to two addressesThe Vantuz control API and the decoy domain. No other site
What it never hasNot requested
Your real cookiesOut of reach: it has no access to the sites you use
Content scriptsIt never runs inside the pages you visit
Tabs and historyIt cannot see which sites you open
webRequestIt cannot watch or change your traffic
Remote codeEverything it runs ships inside the extension
AnalyticsNo tracking and no usage data

WHEN IT FIRES

They get a 404.
You get the whole story.

The decoy domain answers with an ordinary 404, so the attacker learns nothing. Vantuz opens an incident with the first source address, country, network and software, maps it to MITRE ATT&CK T1550.004 (Web Session Cookie) and scores it at least High (62). The alert reaches you by email, with the full investigation in the app.

HighBrowser session16 Sept, 07:52

A decoy browser session was used: Finance laptop

The decoy session lived only in the browser on the finance laptop, and someone replayed it from an address in the United Kingdom. The decoy domain answered with an ordinary 404, so they learned nothing.

SourceGB · hosting network
SoftwareChrome on Windows
TechniqueT1550.004 Web Session Cookie
62Risk score
What to do next
1Confirm with the person who uses that browser.
2Sign them out everywhere and reset their passwords.
3Check the computer for infostealer malware.
4Revoke the decoy, then reconnect the browser.

HONEST LIMITS

What it proves, and what it cannot.

A decoy gives you a certain signal, not the complete picture. Here is exactly where the edges are.

01

It fires only if someone tries it

Attackers often sort through stolen sessions and use only the ones they want. If nobody replays the decoy, it stays quiet, so silence does not prove nothing was taken.

02

It fires on use, not on the copy

Malware can copy the cookie jar and sit on it. The decoy speaks up the moment someone replays the session, not before.

03

It cannot say which real sessions were taken

A replay tells you the browser's sessions were very likely copied. It cannot list which real ones went, so treat them all as exposed and sign the person out everywhere.

04

Opening the address fires it too

Anyone who opens the decoy address in that browser, on purpose or by following a link to it, fires it as well. That is why the first step is to confirm with the person.

TWO WAYS IN

One browser today, or every browser at once.

Both end the same way: one decoy session in each browser, renewed every 6 hours and watched by Vantuz.

One browser

No IT admin needed

For one person, or to try it first. An owner or admin creates the code in Vantuz, the person pastes it into the extension, and the decoy is armed.

  • Decoys › Deploy decoy › Browser session
  • A single-use code, valid for 24 hours
  • Chrome or Edge

Managed fleet

For IT

For the browsers your company manages. IT pushes a policy through Google Admin or Microsoft Intune. New browsers can join for 30 days; browsers that joined keep renewing.

  • Google Admin
  • Microsoft Intune
  • One policy for many browsers

Revoking a decoy disarms it on the server immediately. The extension removes its cookie at its next check.

Use it only on browsers your company controls or has authorised, and let the people who use them know.

EARLY ACCESS

Put a decoy in the browser before someone copies it.

The browser decoy is in early access until Google approves its Chrome Web Store listing. Tell us how many browsers you would like to cover and how you manage them, and we will set you up in the pilot.

SEE IT LIVE

Watch it catch an attack.
Then decide.

Thirty minutes, your environment. We plant a decoy, trigger it on purpose,
and you watch the whole response happen. No slides.

Start free
Prefer a conversation? hello@vantuz.co

COMMON QUESTIONS

Before you
install it.

Something else on your mind?
Can the extension see my browsing or my real cookies?

No. It asks for three permissions, cookies, storage and alarms, and it can reach only two addresses: the Vantuz control API and the decoy domain. Chrome only lets an extension touch cookies on the sites it can reach, so your real sessions, tabs and history stay out of its sight. No content scripts, no remote code, no analytics.

Is it on the Chrome Web Store?

Not yet. The browser decoy is in early access, and it goes on the Chrome Web Store once Google approves the listing. Request early access and we will set it up with you.

Which browsers does it work in?

Google Chrome and Microsoft Edge on desktop, version 120 or later. It is a Manifest V3 extension. In Edge, turn on Allow extensions from other stores before installing it from the Chrome Web Store.

What happens when someone replays the decoy?

The decoy domain answers with an ordinary 404, so the attacker learns nothing. Vantuz opens an incident with the first source address, country, network and software, maps it to MITRE ATT&CK T1550.004 (Web Session Cookie) and scores it at least High (62). You get an email, and the full investigation is in the app.

Can it go off by accident?

Normal browsing never touches the decoy session: it lives on a domain nobody at your company uses. The exceptions are someone opening the decoy address in that browser, on purpose or through a link to it. That is why the first step is always to confirm with the person.

How do I switch it off?

Revoke the decoy in Vantuz. The server disarms it immediately, and the extension removes its cookie at its next check. Then remove the extension or the policy as you would any other.