Technique
Cookie Hijacking
Also known as: Session Hijacking, Pass-the-Cookie, Cookie-Bite, Session Cookie Theft, Token Replay Attack, Cookie Replay Attack
Attackers steal browser session cookies -- typically via infostealer malware, adversary-in-the-middle phishing proxies, or malicious browser extensions -- and replay them in their own browser to hijack authenticated sessions. Because the session is already established past the authentication gate, t…
Common attack flows
How it fits in a scam
Defense
How to defend against this
How to spot it
- Unexpected account activity such as logins
- messages sent
- or settings changes you did not perform
- Security alerts from services about sign-ins from unfamiliar devices
- locations
- or browsers
- Active sessions listed in account security settings that you do not recognize
- Devices listed as trusted in your account that you have never used
- Sudden logouts from services you were previously signed into (attacker session may invalidate yours)
- Notifications of password or recovery email/phone changes you did not initiate
Tools you can use
Steps you can take
Seen in the wild
Where we’ve seen it
Commonly targets
Further reading
FBI Atlanta Field Office
FBI public advisory warning that cybercriminals are stealing Remember-Me cookies to bypass MFA and access victim email accounts
The Hacker News
Analysis of modern session hijacking via infostealers; reports 147,000 token replay attacks detected by Microsoft in 2023 (111% YoY increase) and Google confirming cookie attacks match password-attack volume
MITRE ATT&CK T1539
MITRE ATT&CK technique entry for Steal Web Session Cookie, documenting procedure examples from APT groups and malware families including RedLine Stealer and Lumma Stealer
Security Boulevard
Detailed attack chain analysis identifying RedLine, Raccoon, Vidar, Meta, and Lumma as primary infostealer families used for cookie harvesting
Varonis Threat Labs
Cookie-Bite research demonstrating how malicious browser extensions exfiltrate authentication tokens to bypass MFA and maintain persistent cloud access
Vectra AI
2025 infostealer report: 1.8 billion credentials stolen from 5.8 million devices; infostealers available as MaaS for approximately $200/month
OWASP
OWASP cheat sheet on cookie theft mitigation including server-side session binding and re-authentication strategies
Okta Security
Okta guidance on defending against session hijacking including session duration controls and logout invalidation