• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Cookie Hijacking

Also known as: Session Hijacking, Pass-the-Cookie, Cookie-Bite, Session Cookie Theft, Token Replay Attack, Cookie Replay Attack

COMPROMISE

Attackers steal browser session cookies -- typically via infostealer malware, adversary-in-the-middle phishing proxies, or malicious browser extensions -- and replay them in their own browser to hijack authenticated sessions. Because the session is already established past the authentication gate, t…

Common attack flows

How it fits in a scam

This technique shows up duringCOMPROMISE

Before

  • InfostealerCOMPROMISE
  • Man In The MiddleCOMPROMISE
  • MalvertisingDELIVERY
  • SEO PoisoningDELIVERY
  • +1 more

After

  • Account TakeoverEXPLOITATION
  • Identity TheftEXPLOITATION
  • Email Forwarding PersistencePERSISTENCE
  • Payment Method InjectionPERSISTENCE
  • +1 more

Defense

How to defend against this

How to spot it

  • Unexpected account activity such as logins
  • messages sent
  • or settings changes you did not perform
  • Security alerts from services about sign-ins from unfamiliar devices
  • locations
  • or browsers
  • Active sessions listed in account security settings that you do not recognize
  • Devices listed as trusted in your account that you have never used
  • Sudden logouts from services you were previously signed into (attacker session may invalidate yours)
  • Notifications of password or recovery email/phone changes you did not initiate

Tools you can use

  • Antivirus SoftwareCost low · Effect medium
  • Hardware Security KeysCost medium · Effect high
  • Password ManagerCost low · Effect high
  • Browser Security ExtensionCost low · Effect medium

Steps you can take

  • Browser Extension AuditCost low · Effect medium
  • Avoid Pirated SoftwareCost low · Effect high
  • Official App Store OnlyCost low · Effect medium

Seen in the wild

Where we’ve seen it

Commonly targets

  • Gamer

Further reading

  • FBI Atlanta Field Office

    FBI public advisory warning that cybercriminals are stealing Remember-Me cookies to bypass MFA and access victim email accounts

  • The Hacker News

    Analysis of modern session hijacking via infostealers; reports 147,000 token replay attacks detected by Microsoft in 2023 (111% YoY increase) and Google confirming cookie attacks match password-attack volume

  • MITRE ATT&CK T1539

    MITRE ATT&CK technique entry for Steal Web Session Cookie, documenting procedure examples from APT groups and malware families including RedLine Stealer and Lumma Stealer

  • Security Boulevard

    Detailed attack chain analysis identifying RedLine, Raccoon, Vidar, Meta, and Lumma as primary infostealer families used for cookie harvesting

  • Varonis Threat Labs

    Cookie-Bite research demonstrating how malicious browser extensions exfiltrate authentication tokens to bypass MFA and maintain persistent cloud access

  • Vectra AI

    2025 infostealer report: 1.8 billion credentials stolen from 5.8 million devices; infostealers available as MaaS for approximately $200/month

  • OWASP

    OWASP cheat sheet on cookie theft mitigation including server-side session binding and re-authentication strategies

  • Okta Security

    Okta guidance on defending against session hijacking including session duration controls and logout invalidation

Related techniques

Variants

  • Session Token Theft

Same stage

  • Credential Theft
  • SIM Swap
  • MFA Fatigue Attack
  • Clipboard Hijacking
  • Malicious App Installation
  • +8 more

Similar defense

  • Data Breach Harvesting
  • Remote Access Tool
  • Tech Support Scam
  • Malvertising
  • Smishing
  • +15 more