Master of Web Puppets: Abusing Web Browsers for Persistent and Stealthy Computation
Panagiotis Papadopoulos, Panagiotis Ilia, Michalis Polychronakis, Evangelos P. Markatos, Sotiris Ioannidis, Giorgos Vasiliadis
Abstract
The proliferation of web applications has essentially transformed modern browsers into small but powerful operating systems. Upon visiting a website, user devices run implicitly trusted script code, the execution of which is confined within the browser to prevent any interference with the user's system. Recent JavaScript APIs, however, provide advanced capabilities that not only enable feature-rich web applications, but also allow attackers to perform malicious operations despite the confined nature of JavaScript code execution. In this paper, we demonstrate the powerful capabilities that modern browser APIs provide to attackers by presenting MarioNet: a framework that allows a remote malicious entity to control a visitor's browser and abuse its resources for unwanted computation or harmful operations, such as cryptocurrency mining, password-cracking, and DDoS. MarioNet relies solely on already available HTML5 APIs, without requiring the installation of any additional software. In contrast to previous browser-based botnets, the persistence and stealthiness characteristics of MarioNet allow the malicious computations to continue in the background of the browser even after the user closes the window or tab of the initial malicious website. We present the design, implementation, and evaluation of a prototype system, MarioNet, that is compatible with all major browsers, and discuss potential defense strategies to counter the threat of such persistent in-browser attacks. Our main goal is to raise awareness regarding this new class of attacks, and inform the design of future browser APIs so that they provide a more secure client-side environment for web applications.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c732548b-bed7-4ef3-a11f-df059dbec09aCited by top-tier papers6
- Slimium: Debloating the Chromium Browser with Feature SubsettingChenxiong Qian, Hyungjoon Koo, ChangSeok Oh, Taesoo Kim et al.CCS 2020 · 35 citations
- InviCloak: An End-to-End Approach to Privacy and Performance in Web Content DistributionShihan Lin, Rui Xin, Aayush Goel, Xiaowei YangCCS 2022 · 5 citations
- WEBRR: A Forensic System for Replaying and Investigating Web-Based Attacks in The Modern WebJoey Allen, Zheng Yang, Feng Xiao, Matthew Landen et al.USENIX Security 2024 · 2 citations
- Melting Pot of Origins: Compromising the Intermediary Web Services that Rehost WebsitesTakuya Watanabe, Eitaro Shioji, Mitsuaki Akiyama, Tatsuya MoriNDSS 2020
- Awakening the Web's Sleeper Agents: Misusing Service Workers for Privacy LeakageSoroush Karami, Panagiotis Ilia, Jason PolakisNDSS 2021
Builds on1
Related papers
- Peripheral Instinct: How External Devices Breach Browser SandboxesLeon Trampert, Lorenz Hetterich, Lukas Gerlach, Mona Schappert et al.WWW 2025 · 2 citations
- MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its DefenseRadhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer et al.CCS 2018 · 162 citations
- MinerRay: Semantics-Aware Analysis for Ever-Evolving Cryptojacking DetectionAlan Romano, Yunhui Zheng, Weihang WangASE 2020 · 30 citations
- Beast in the Cage: A Fine-grained and Object-oriented Permission System to Confine JavaScript Operations on the WebRui ZhaoWWW 2025 · 2 citations
- JavaScript Zero: Real JavaScript and Zero Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel GrussNDSS 2018 · 67 citations
