logo

New Pass-the-Cookie Attacks Bypass MFA, Giving Hackers Full Account Access

ID: 1566175a-97a6-57fd-89ef-816d35154fb1

STIX ID: report--1566175a-97a6-57fd-89ef-816d35154fb1

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: Divya

...
...

Pass-the-Cookie attacks exploit stolen browser session cookies (e.g., ESTSAUTH) harvested by infostealer malware to bypass MFA and gain persistent access to Office 365/Azure accounts; the report includes a proof-of-concept, identifies malware families (LummaC2, Redline, Racoon), notes a substantial increase in cookie-theft activity, and recommends mitigations such as session token monitoring, conditional access, Continuous Access Evaluation, and strengthened EDR controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.