Browser-data theft is one of the most consistently documented Millenium RAT capabilities. Public research reports theft of browser credentials, browser cookies, browsing history, stored browser information, downloaded-file metadata, and potentially saved payment-card information where available.
Cookie theft is particularly significant because it can enable session hijacking — bypassing some forms of authentication that rely on a valid session cookie rather than a re-entered password. Stolen credentials provide direct access to accounts; stolen cookies can provide access even when MFA is in place, depending on the session model.
This capability is documented across both the .NET 2.x versions (CYFIRMA, Symantec, 2023) and the native C++ 4.x branch (Group-IB, 2026). The defensive implication is that browser-credential-store access by unexpected processes is a high-value endpoint detection signal, and that credential rotation and session revocation are essential after a confirmed infection.

