Skip to main content

This page is also available in Türkçe.

Switch language
Infostealers

How infostealers walk straight past your MFA

Multi-factor authentication stops password reuse. It does not stop a stolen session cookie — and that is exactly what modern stealer logs contain.

2 min read

Multi-factor authentication is the single highest-value control most organizations deploy. It is also routinely bypassed — not by breaking the cryptography, but by skipping the login entirely.

The password is not the prize

When an infostealer runs on a machine, it does not stop at saved passwords. It takes the browser’s cookie jar, local storage, and any authentication tokens it can reach. Among those cookies are session identifiers for every service the user was signed into.

A session cookie represents an already-authenticated state. Replaying it does not trigger a password prompt, and it does not trigger a second factor — the server has already been told this session passed both.

What this looks like in practice

  1. A user installs cracked software, or opens a malicious attachment, on a personal or lightly-managed machine.
  2. The stealer harvests credentials and cookies and exfiltrates them within seconds.
  3. The log is packaged and sold, often within hours.
  4. A buyer imports the cookies into their own browser and lands inside the session — mail, SSO dashboard, VPN portal, cloud console.

No alert fires for a failed login, because there was no login.

What actually helps

  • Short session lifetimes on anything privileged. A cookie stolen on Tuesday is worthless on Wednesday.
  • Token binding and device checks so a session presented from an unfamiliar device or network is re-challenged.
  • Phishing-resistant factors (passkeys, hardware keys) for the accounts that matter most — they raise the cost of the initial credential theft too.
  • Detection of the exposure itself. If you learn a device was compromised, you can revoke every session it held before anyone replays them.

The detection gap

That last point is the one most programmes are missing. The technical controls raise the bar; they do not tell you that a specific laptop belonging to a specific employee gave up a specific set of live sessions three days ago. That signal exists — it is sitting in the stealer log — but only if someone is matching those logs against your domains.

Revoking a session takes a minute. Knowing which one to revoke is the hard part.

Breach assessment

Run it against your own domains

A time-boxed assessment on the domains you register — your real exposure, not synthetic or sample data, and no procurement cycle to start one.

  1. A scoping call Which domains, brands and suppliers matter, and what you need to be able to prove internally.
  2. A live walkthrough The console, your exposure, and how a finding moves from detection to a closed ticket.
  3. A real report Sanitized, masked and structured the way you would present it to your leadership.
  4. A clear next step If the exposure does not justify a programme, we will tell you that.

Masked evidence by default · Tenant-isolated · Encrypted in transit and at rest · Nothing deployed in your estate