Phishing Kits Steal Valid Sessions, Moving Attacks Beyond MFA

· Original article ↗

Summary

The article explains how phishing kits and infostealer malware steal authenticated sessions, letting attackers access accounts after successful MFA. It recommends revoking sessions and refresh tokens, improving post-login detection, and limiting account privileges.

Key points

  • The NovaCookies adversary-in-the-middle service reportedly rents for $320 a month and relays Microsoft 365 logins to capture authenticated sessions.
  • NovaCookies campaigns use phishing lures, including counterfeit document-sharing messages, and infrastructure designed to evade email scanners.
  • ANY.RUN data on Mirage2FA activity estimates 4,532 potentially compromised addresses among 9,426 targets; the article cautions these figures are estimates, not independently confirmed compromises.
  • The article describes Anthropic notifying users whose Claude sessions were stolen by infostealer malware, including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer.
  • Anthropic signed affected users out, removed saved payment methods, and refunded charges it identified as unauthorized; the article warns that signing out does not remove malware.
  • Recommended defenses include revoking active sessions and refresh tokens, prioritizing phishing-resistant authentication for privileged accounts, monitoring post-login behavior, and limiting standing privileges.

Article Details

Topic
Theft and replay of authenticated web sessions to bypass multi-factor authentication

MITRE ATT&CK

Malware

Vendors

Products

Tools

Countries

Related Articles