• Tech News
    • Games
    • Pc & Laptop
    • Mobile Tech
    • Ar & Vr
    • Security
  • Startup
    • Fintech
  • Reviews
  • How To
What's Hot

Elementor #32036

January 24, 2025

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

April 18, 2024

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

April 16, 2024
Facebook Twitter Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook Twitter Instagram Pinterest VKontakte
Behind The ScreenBehind The Screen
  • Tech News
    1. Games
    2. Pc & Laptop
    3. Mobile Tech
    4. Ar & Vr
    5. Security
    6. View All

    Bring Elden Ring to the table with the upcoming board game adaptation

    September 19, 2022

    ONI: Road to be the Mightiest Oni reveals its opening movie

    September 19, 2022

    GTA 6 images and footage allegedly leak

    September 19, 2022

    Wild west adventure Card Cowboy turns cards into weird and silly stories

    September 18, 2022

    7 Reasons Why You Should Study PHP Programming Language

    October 19, 2022

    Logitech MX Master 3S and MX Keys Combo for Business Gen 2 Review

    October 9, 2022

    Lenovo ThinkPad X1 Carbon Gen10 Review

    September 18, 2022

    Lenovo IdeaPad 5i Chromebook, 16-inch+120Hz

    September 3, 2022

    It’s 2023 and Spotify Still Can’t Say When AirPlay 2 Support Will Arrive

    April 4, 2023

    YouTube adds very convenient iPhone homescreen widgets

    October 15, 2022

    Google finishes iOS 16 Lock Screen widgets rollout w/ Maps

    October 14, 2022

    Is Apple actually turning iMessage into AIM or is this sketchy redesign rumor for laughs?

    October 14, 2022

    MeetKai launches AI-powered metaverse, starting with a billboard in Times Square

    August 10, 2022

    The DeanBeat: RP1 simulates putting 4,000 people together in a single metaverse plaza

    August 10, 2022

    Improving the customer experience with virtual and augmented reality

    August 10, 2022

    Why the metaverse won’t fall to Clubhouse’s fate

    August 10, 2022

    How Apple privacy changes have forced social media marketing to evolve

    October 16, 2022

    Microsoft Patch Tuesday October Fixed 85 Vulnerabilities – Latest Hacking News

    October 16, 2022

    Decentralization and KYC compliance: Critical concepts in sovereign policy

    October 15, 2022

    What Thoma Bravo’s latest acquisition reveals about identity management

    October 14, 2022

    What is a Service Robot? The vision of an intelligent service application is possible.

    November 7, 2022

    Tom Brady just chucked another Microsoft Surface tablet

    September 18, 2022

    The best AIO coolers for your PC in 2022

    September 18, 2022

    YC’s Michael Seibel clarifies some misconceptions about the accelerator • DailyTech

    September 18, 2022
  • Startup
    • Fintech
  • Reviews
  • How To
Behind The ScreenBehind The Screen
Home»Tech News»Growing MFA use spurs ‘pass-the-cookie’ attacks
Tech News

Growing MFA use spurs ‘pass-the-cookie’ attacks

August 19, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Growing MFA use spurs ‘pass-the-cookie’ attacks
Share
Facebook Twitter LinkedIn Pinterest Email

The tried-and-true technique of using stolen session cookies to bypass multifactor authentication (MFA) protections and gain access to key systems has increased massively in recent months, according to intelligence published today by Sophos.

Such attacks – often referred to as pass-the-cookie attacks – are of course nothing new. Indeed, they have long been an established tool in the cyber criminal’s arsenal because, ultimately, they enable attackers to assume the persona of a legitimate user and do anything the legitimate user can.

In June 2022, Microsoft spilled the beans on a large-scale phishing campaign that hit 10,000 of its customers by using phishing sites to steal passwords, hijack sign-in sessions, and bypass top-of-the-line MFA features. And there have been multiple warnings before that, including an alert from US cyber authority CISA in early 2021.

They work like this. A session or authentication cookie, which is stored by a web browser when a user logs into a web-based resource, can, if stolen, be injected into a new web session to trick the browser into thinking the authenticated user is present and does not need to prove their identity. Because such a token is also created and stored on a web browser when MFA is in play, the same technique can handily be used to bypass it.

This problem is compounded by the fact that many web-based applications have long-lived cookies that rarely expire, or only do so if the user specifically logs out of the service.

In a new report, Cookie stealing: the new perimeter bypass, Sophos’s newly established X-Ops unit said these attacks are becoming increasingly prevalent thanks to the growing popularity of MFA tools.

See also  Android 13 arrives for Pixel phones

Access to pass-the-cookie attacks is trivial for a threat actor, said X-Ops – in many cases, all they would need to do is obtain a copy of an infostealer, such as Raccoon Stealer, to collect credential data and cookies in bulk and sell them on to others – even ransomware gangs – on the dark web.

“Attackers are turning to new and improved versions of information stealing malware to simplify the process of obtaining authentication cookies – also known as access tokens,” said Sean Gallagher, principal threat researcher at Sophos. “If attackers have session cookies, they can move freely around a network, impersonating legitimate users.”

In many cases, said X-Ops, the act of cookie theft is becoming a much more highly targeted attack, with adversaries scraping cookie data from within a network and using legitimate executables to hide their activity.

In one case that Sophos responded to, an attacker used an exploit kit to establish access, and then a combination of the Cobalt Strike and Meterpreter tools to abuse a legitimate compiler tool and scrape access tokens. They spent months inside their victim’s network gathering cookies from the Microsoft Edge browser.

The end goal is to obtain access to the victim’s web-based or cloud-hosted resources, which can then be used for further exploitation, such as business email compromise, social engineering to gain access to additional systems, or even modification of the victim’s data or source code repositories.

“While historically we’ve seen bulk cookie theft, attackers are now taking a targeted and precise approach to cookie stealing,” said Gallagher. “Because so much of the workplace has become web-based, there really is no end to the types of malicious activity attackers can carry out with stolen session cookies.

See also  Slippery phish wriggles round MFA protections, says Microsoft

“They can tamper with cloud infrastructures, compromise business email, convince other employees to download malware or even rewrite code for products. The only limitation is their own creativity.”

Gallagher added: “Complicating matters is that there is no easy fix. For example, services can shorten the lifespan of cookies, but that means users must re-authenticate more often, and, as attackers turn to legitimate applications to scrape cookies, companies need to combine malware detection with behavioural analysis.”

Source link

attacks growing MFA passthecookie spurs
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

How AI Protects (and Attacks) Your Inbox

June 3, 2023

9 Lessons From Unicorn-Builder Marc Andreessen For Growing Ventures

May 19, 2023

Staying Resilient And Growing Your Mindset

May 5, 2023

Advice for entrepreneurs in the medical device industry on raising cash and growing startups – Startup

November 22, 2022
Add A Comment

Comments are closed.

Editors Picks

Pups & Purrs Pet Shop is coming west

July 5, 2022

How To Create A Viral Loop

July 11, 2022

Instagram was fined $402 million in the EU for making young users’ data public

September 6, 2022

After big slowdown in IPO and M&A activity, analysts optimistic for a rebound – Startup

January 27, 2023

Subscribe to Updates

Get the latest news and Updates from Behind The Scene about Tech, Startup and more.

Top Post

Elementor #32036

The Redmi Note 13 is a bigger downgrade compared to the 5G model than you might think

Xiaomi Redmi Watch 4 is a budget smartwatch with a premium look and feel

Behind The Screen
Facebook Twitter Instagram Pinterest Vimeo YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 behindthescreen.uk - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.