'Cookie Bite' Entra ID Attack Exposes Microsoft 365
ID: 2bcfd9b4-b505-5768-9608-73b63768ef12
STIX ID: report--2bcfd9b4-b505-5768-9608-73b63768ef12
Feed Name: Dark Reading
Date Published: 2025-04-22
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Researchers at Varonis published a PoC named "Cookie Bite" that extracts Azure Entra ID session cookies (ESTSAUTH and ESTSAUTHPERSISTENT) using a browser extension and PowerShell for persistent cookie-stealing and session hijacking. The technique can bypass MFA, grant persistent access to Microsoft 365 resources (Outlook, Teams, etc.), and is described as evasive and widely applicable; the report details attack stages, detection guidance, and mitigations such as enforcing extension allowlists and monitoring sign-in risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
