Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks
ID: 265a8c68-adf2-58e0-811d-e019f5e1f1dd
STIX ID: report--265a8c68-adf2-58e0-811d-e019f5e1f1dd
Feed Name: GBHackers
Threat Score
Infostealer malware is quietly harvesting browser-saved credentials, session cookies, and other sensitive data, which are aggregated into searchable stealer-log markets and resold to initial access brokers and ransomware affiliates; stolen session cookies are highlighted as a primary method for bypassing MFA and enabling direct access to corporate networks, with large-scale circulation (e.g., 124 million unique passwords) and distribution via channels like Telegram.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
