logo

'Cookie Bite' Entra ID Attack Exposes Microsoft 365

ID: 2bcfd9b4-b505-5768-9608-73b63768ef12

STIX ID: report--2bcfd9b4-b505-5768-9608-73b63768ef12

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-04-22

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers at Varonis published a PoC named "Cookie Bite" that extracts Azure Entra ID session cookies (ESTSAUTH and ESTSAUTHPERSISTENT) using a browser extension and PowerShell for persistent cookie-stealing and session hijacking. The technique can bypass MFA, grant persistent access to Microsoft 365 resources (Outlook, Teams, etc.), and is described as evasive and widely applicable; the report details attack stages, detection guidance, and mitigations such as enforcing extension allowlists and monitoring sign-in risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.