What Is an Infostealer? Session Cookie and Token Theft That Bypasses MFA
An infostealer steals browser passwords and session cookies. How a stolen cookie bypasses MFA, the symptoms, the first 24 hours and layers of defense.
Quick answer: An infostealer is a type of malware that collects browser passwords, session cookies, authentication tokens, crypto wallets and autofill data from an infected device and sends them to an attacker. Its most dangerous feature is the stolen session cookie. Because a cookie represents an already authenticated session, an attacker can use it to enter an account without being asked again for the password or multi factor authentication (MFA).
How does an infostealer work?
An infostealer usually runs quietly. Unlike ransomware it does not try to attract attention, it silently collects data and leaves the device. On infection a typical infostealer targets:
- Usernames and passwords saved in the browser
- Active session cookies and authentication tokens
- Autofill data and credit card details
- Crypto wallet files and keys
- Documents on the desktop, screenshots and system information
The collected data package (a log) is often sold on underground markets. So the group that performs the initial infection can differ from the group that ultimately abuses the account. This split explains why an intrusion is often noticed weeks after the infection.
Why does session cookie theft bypass MFA?
Multi factor authentication asks for extra proof beyond the password. But this check happens only at sign in. Once authentication completes, the server issues a session cookie to the browser. That cookie means "this user is already verified."
The infostealer steals exactly this cookie. When the attacker loads the stolen cookie into their own browser, the server treats it as a continuation of the verified session. No password is asked, no MFA is asked. This technique is called "pass-the-cookie" and in the MITRE ATT&CK framework it is classified as use of alternate authentication material via a web session cookie.
The conclusion matters. A strong password and MFA are effective against phishing and brute force. But if the device is already compromised by an infostealer, the attacker skips the authentication step entirely. This is why infostealer defense is not solved by password policy alone.
Symptoms and infection paths
An infostealer usually arrives through a file the user runs themselves. The most common paths are:
| Infection path | Example scenario |
|---|---|
| Fake or cracked software | A crack or keygen downloaded by a user looking for a free version |
| Malvertising | A fake download page shown at the top of search results |
| Phishing attachment | A compressed file disguised as an invoice, shipment or resume |
| Fake update | An imitation of a browser or media player update |
| Trojan extension | A browser extension containing malicious code |
Post infection symptoms are often subtle. Sign in notifications from unfamiliar locations, unexpected changes in account settings, sent emails that you never sent, and access that happens without any MFA prompt are all signs to watch for.
The first 24 hours after infection
If you suspect an infostealer on a device, changing the password alone is not enough. If a stolen cookie is still valid, the attacker can stay in the session even after you change the password. The correct order is:
- Isolate the affected device from the network and take an image (preserve evidence for forensics).
- Terminate all active sessions on the related accounts, that is, revoke the tokens. This step is the most critical in cookie theft.
- Reset passwords from a clean device.
- Prioritize administrator and single sign on (SSO) accounts.
- Review the logs to determine which accounts and data the attacker accessed.
Layers of defense
Defense against infostealers is not a single product but a layered approach.
| Layer | Control |
|---|---|
| Device | Behavior based detection with EDR/MDR, application allowlisting |
| Identity | Short session lifetime, device bound sessions, risky session termination |
| User | Awareness of fake software and cracked licenses, phishing training |
| Browser | Enterprise profile, ban on unnecessary extensions |
| Monitoring | Leak and dark web monitoring to detect stolen credentials |
The KAOS and DSET approach
DSET performs digital forensics and incident response (DFIR) on devices suspected of infostealer infection. We determine which data the malware accessed, which sessions were stolen and the attacker's next steps from the logs. Our KAOS security engine reports leaked credentials and weak session management during enterprise attack surface scans. Our goal is evidence based response, not exaggerated threat narratives.
Related reading: fileless malware and LOLBins, leaked passwords and credential stuffing, using a password manager, Windows event log forensics, dark web and data leak monitoring.
Frequently asked questions
Does an infostealer really bypass MFA? Yes, indirectly. An infostealer does not crack the password or MFA, it steals the session cookie issued after authentication completes. Because that cookie represents an already verified session, the attacker uses it to sign in without being asked again for password or MFA. For defense, revoking sessions (token revoke) is a higher priority than changing the password.
How do I know if my device has an infostealer? A definite diagnosis usually requires forensic examination because infostealers run silently. Warning signs are sign in notifications from unfamiliar locations, unexpected changes in account settings, and access you did not initiate. If in doubt, isolating the device and having it examined is the safest path.
I changed my password, is that enough? It may not be enough on its own. If the attacker holds a valid session cookie, they can remain in the session with that cookie even after you change the password. That is why you should first terminate all active sessions, then reset the password from a clean device.
Sources
- MITRE ATT&CK, Credentials from Password Stores (T1555) and Steal Web Session Cookie (T1539): attack.mitre.org
- CISA, guidance on phishing and credential theft: cisa.gov
- DSET Blog, leaked passwords and credential stuffing
For forensics and response in an incident with suspected infostealer activity, you can talk to our team at Ankara Hacettepe Technopark. Contact DSET.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.