New Pass-the-Cookie Attacks Bypass MFA, Giving Hackers Full Account Access
ID: 1566175a-97a6-57fd-89ef-816d35154fb1
STIX ID: report--1566175a-97a6-57fd-89ef-816d35154fb1
Feed Name: GBHackers
Threat Score
Pass-the-Cookie attacks exploit stolen browser session cookies (e.g., ESTSAUTH) harvested by infostealer malware to bypass MFA and gain persistent access to Office 365/Azure accounts; the report includes a proof-of-concept, identifies malware families (LummaC2, Redline, Racoon), notes a substantial increase in cookie-theft activity, and recommends mitigations such as session token monitoring, conditional access, Continuous Access Evaluation, and strengthened EDR controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
