BeEF, short for Browser Exploitation Framework, is an open-source post-exploitation framework focused on abusing web browsers as an attack surface. It is commonly used after a victim browser is hooked through injected or embedded JavaScript, enabling operators to profile the browser and user environment, run client-side commands, deliver social-engineering content, and support follow-on exploitation. BeEF is frequently associated with strategic web compromise, phishing infrastructure, and cross-site scripting-driven operations rather than with standalone malware deployment.
The framework has been observed in intrusion activity where compromised or malicious websites injected scripts that loaded BeEF to interact with visiting browsers. Reported use cases include phishing pages, watering-hole operations, and malicious redirects from compromised government or news-related sites. Threat actors have used BeEF alongside other offensive tooling such as ScanBox, Cobalt Strike, Meterpreter, and custom web exploitation frameworks. Public reporting has linked its operational use to multiple espionage-oriented campaigns, including activity attributed to China-aligned groups such as LuckyMouse and Earth Empusa, as well as broader attacker tradecraft involving webmail and browser-based compromise.
BeEF’s role is best understood as a browser exploitation and control framework that supports reconnaissance and post-exploitation in the browser context. It can help operators identify browser characteristics, interact with hooked sessions, and facilitate additional malicious actions through the victim’s browser. Because it is a framework rather than a self-propagating payload family, its delivery typically depends on prior compromise of a website, phishing page, or injected script that causes a target browser to load the BeEF hook.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
All pages were injected with a script to load the cross-site scripting framework BeEF.
"...redirected users to malicious sites hosting exploitation tools such as ScanBox and BEeF (Browser Exploitation Framework)."
"...redirected users to malicious sites hosting exploitation tools such as ScanBox and BEeF (Browser Exploitation Framework)."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
JavaScript - Individual Risks ... Drive-by-exploitation still a topic in 2015 ... Great Cannon: Easier than Man-on-the-side
Cross-Site Scripting is usually a client-side issue... an attacker can leverage XSS to ultimately achieve code execution on the server... the attacker uses XSS as a form of remote control of an admin’s browser.
Recorded Future tracks the creation and modification of new malicious infrastructure for a multitude of post-exploitation toolkits, custom malware, and open-source remote access trojans (RATs). We observed over 17,000 unique command-and-control (C2) servers during 2022...
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a standard XSS/browser exploitation toolkit for comparison against the custom APT28 implant.
BeEF is mentioned in the context of a demo related to browser-based attack techniques.
Browser exploitation framework mentioned as the basis for a malware delivery platform tied to Boolka infrastructure.
Browser exploitation framework listed among the attacker-accessible tooling hosted in the Alibaba cloud container registry.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.