Phishing Kits Steal Valid Sessions, Moving Attacks Beyond MFA

Summary
The article explains how phishing kits and infostealer malware steal authenticated sessions, letting attackers access accounts after successful MFA. It recommends revoking sessions and refresh tokens, improving post-login detection, and limiting account privileges.
Key points
- The NovaCookies adversary-in-the-middle service reportedly rents for $320 a month and relays Microsoft 365 logins to capture authenticated sessions.
- NovaCookies campaigns use phishing lures, including counterfeit document-sharing messages, and infrastructure designed to evade email scanners.
- ANY.RUN data on Mirage2FA activity estimates 4,532 potentially compromised addresses among 9,426 targets; the article cautions these figures are estimates, not independently confirmed compromises.
- The article describes Anthropic notifying users whose Claude sessions were stolen by infostealer malware, including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer.
- Anthropic signed affected users out, removed saved payment methods, and refunded charges it identified as unauthorized; the article warns that signing out does not remove malware.
- Recommended defenses include revoking active sessions and refresh tokens, prioritizing phishing-resistant authentication for privileged accounts, monitoring post-login behavior, and limiting standing privileges.
Article Details
- Topic
- Theft and replay of authenticated web sessions to bypass multi-factor authentication
MITRE ATT&CK
Malware
AcreedThe malware involved was not novel or targeted. Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a smaller number of Macs. These families steal whatever is storedAtomic Stealeror targeted. Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a smaller number of Macs. These families steal whatever is stored locally, including browserLummaC2The malware involved was not novel or targeted. Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a smaller number of Macs. These families steal whatever is storedRedLineThe malware involved was not novel or targeted. Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a smaller number of Macs. These families steal whatever is storedStealCThe malware involved was not novel or targeted. Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a smaller number of Macs. These families steal whatever is storedVidarThe malware involved was not novel or targeted. Anthropic identified Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer on a smaller number of Macs. These families steal whatever is stored
Vendors
Anthropicto organizations with weak hygiene. In the last week, in a notice sent directly to affected users, Anthropic began notifying users whose active Claude login sessions had been lifted off their own machines byMicrosofttrial. For that price the operator supplies lures, domains, hosting, redirects, and support, and relays Microsoft 365 logins in real time in order to capture the authenticated session. The service is reported to be
Products
Claudethe last week, in a notice sent directly to affected users, Anthropic began notifying users whose active Claude login sessions had been lifted off their own machines by commodity infostealer malware, and then replayedMicrosoft 365For that price the operator supplies lures, domains, hosting, redirects, and support, and relays Microsoft 365 logins in real time in order to capture the authenticated session. The service is reported to be
Tools
Mirage2FAA second toolkit, Mirage2FA, gives some sense of the volume. The figures come from vendor research published by ANY.RUN, and they should be read with the caveat the researchers themselves attach: every victim andNovaCookiesof at least two commercial phishing services running right now, one of them a $320-a-month kit called NovaCookies, and it is what happened to a set of customers at one of the most security-literate software companies