< ciso
brief />
Tag Banner

All news with #session hijacking tag

33 articles

Mirage2FA Surge: Microsoft 365 Session Hijacks Rise

πŸ›‘οΈ The Mirage2FA campaign (2024–2026) has impacted thousands of organizations by abusing legitimate Microsoft 365 login flows to bypass two-factor authentication. ANY.RUN research links the activity to 4,532 unique organization domains, with 63.7% of victims in the US and others across multiple regions. Attackers steal passwords and session cookies to hijack authenticated sessions, enabling impersonation, fraud, and access to SSO-connected services.
read more β†’

AmnesiaStealer macOS malware hijacks browser sessions

πŸ›‘οΈ A new macOS infostealer called AmnesiaStealer uses ClickFix campaigns to deliver a Mach-O payload inside a password-protected archive. It copies Chromium profiles and launches hidden, headless browser instances to preserve authentication state while enabling remote operator control. The malware exfiltrates passwords, keychain items, crypto wallets, browser data across 16 Chromium-based browsers, and streams live screencasts and input via WebSocket channels. Researchers at Jamf warn the module abuses the Chrome DevTools Protocol to let attackers navigate and act in victims' authenticated sessions.
read more β†’

NatJack NAT manipulation hijacks TCP sessions

πŸ”’ Researcher Malcolm Stagg disclosed NatJack, a class of attacks that manipulates NAT connection state to hijack TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the work found vulnerable behaviors across multiple implementations including Windows and Linux, with two CVEs assigned: CVE-2026-56181 and CVE-2026-63913. Mitigations include applying vendor updates, segregating untrusted workloads, encrypting internal traffic, and employing IP Source Guard where possible.
read more β†’

NatJack at Black Hat: NAT trust model under test

πŸ›‘οΈ At Black Hat USA 2026, researcher Malcolm Stagg disclosed NatJack, a class of attacks that manipulates NAT connection tracking tables to hijack TCP connections, poison DNS, and cause DoS without needing IP spoofing or Layer 2 access. Testing across 32 products revealed vulnerabilities in every implementation examined. Vendor responses varied from patches and CVEs to arguments that the issues reflect design limitations rather than security flaws. Stagg recommended monitoring NAT tables, enabling source IP protections, segmenting untrusted traffic, and disabling loose connection tracking modes as mitigations.
read more β†’

Insurance Phishing Evolves into Real-Time Account Hijacks

πŸ” Recent research shows insurance-targeted phishing has shifted from credential harvesting to real-time session hijacking. Attackers use paid Google Ads and disposable hosting to lure victims to realistic portals and then relay OTPs and credentials to authenticate on the legitimate service while the victim is logged in. CTM360 identified a bespoke kit, InsureOTP Kit, and exposed backend infrastructure revealing live session management and operator workflows. Defenders must expand detection beyond malicious pages to include ad monitoring, infrastructure analysis, and attacker workflow intelligence.
read more β†’

Authorities dismantle major Kratos phishing infrastructure

πŸ›‘οΈ German and US law enforcement dismantled the core infrastructure of the Kratos phishing kit and arrested a developer in Indonesia. Investigators disabled over 200 servers; authorities estimate about 1,800 customers ran roughly 15,000 phishing campaigns per month. Kratos stole credentials and session cookies, enabling adversary-in-the-middle bypasses of MFA and persistent access to Microsoft 365 accounts.
read more β†’

Bluekit adopts browser-in-the-middle for login theft

πŸ›‘οΈ The Bluekit phishing-as-a-service platform has added browser-in-the-middle (BitM) capabilities and nearly 70 new hostnames, enabling attackers to load legitimate login pages and capture valid session tokens. Netcraft found Bluekit uses the open-source rrweb library to serialize and stream page DOM data over WebSockets while fetching assets through phishing infrastructure. The kit also includes advanced anti-analysis features such as randomized CSS filters, large rotating obfuscated JavaScript bundles, custom CAPTCHAs, browser fingerprinting, and WebRTC IP-mismatch checks.
read more β†’

SilabRAT malware targets crypto via session hijacks

πŸ›‘οΈ Group-IB reports a new MaaS remote access trojan called SilabRAT, advertised since late 2025 and offered on dark web forums. The malware uses a hidden VNC (HVNC) and browser-profile cloning to hijack logged-in sessions and evade passwords and MFA, while operators spread it via spam and ClickFix lures. Its capabilities include keystroke logging, clipboard clippers, COM elevation to bypass Chrome app-bound encryption, and persistent access aimed at stealing cryptocurrency.
read more β†’

Siemens SIPROTEC 5 Session ID Randomness Vulnerability

⚠️ The Siemens SIPROTEC 5 series employs insufficiently random values for session identifiers on a subset of web endpoints, enabling an unauthenticated remote actor to brute-force and hijack valid sessions. Exploitation can permit limited read access to web server information without authorization. Siemens is preparing fixes and recommends updating to V11.0 or later where available, validating updates, and applying network protections such as segmentation, firewalls, and controlled remote access procedures.
read more β†’

CloudZ RAT and Pheno Plugin Abuse Microsoft Phone Link

πŸ” Cisco Talos has observed the CloudZ RAT paired with a previously undocumented plugin, Pheno, harvesting SMS messages and one-time passwords by abusing Microsoft's Phone Link functionality. Pheno scans for Phone Link processes and confirms active paired sessions before extracting synced SMS content from local SQLite files, allowing attackers to capture OTPs without touching the victim's mobile device. Observed since January 2026, the campaign uses a Rust loader, a .NET payload deployed via regasm.exe, and multiple anti-analysis techniques; Talos published IoCs and ClamAV signatures to aid detection.
read more β†’

Vishing and SSO Abuse Drive Rapid SaaS Extortion Campaigns

πŸ”’ Cybercrime clusters Cordial Spider and Snarky Spider are executing fast, low-footprint extortion campaigns that rely on vishing and SSO adversary-in-the-middle pages to harvest credentials and MFA codes. After registering devices and suppressing notification emails, attackers pivot directly into SaaS platforms such as Google Workspace, HubSpot, SharePoint, and Salesforce to locate and exfiltrate high-value files. Researchers note heavy use of living-off-the-land techniques and residential proxies to minimize detection.
read more β†’

Stopping AiTM Phishing: Defenses After Authentication

πŸ›‘οΈ AiTM phishing evades credential theft by intercepting session tokens after legitimate logins, rendering stronger passwords and many MFA approaches insufficient on their own. While FIDO2 and passkeys reduce exposure at the authentication step, session cookies remain bearer tokens that can be replayed. The article recommends three practical controlsβ€”bind sessions to managed devices, monitor post-authentication anomalies, and shorten high-value session lifetimesβ€”combined with targeted user guidance to stop attackers from exploiting captured sessions.
read more β†’

Storm infostealer hijacks sessions, decrypts server-side

⚠️ A new infostealer dubbed Storm surfaced on underground marketplaces in early 2026, offering subscription-based credential and session theft for under $1,000 per month. Storm harvests browser passwords, session cookies, crypto wallets, autofill data, and app tokens, then uploads encrypted artifacts and performs server-side decryption to evade endpoint detection. The platform also automates cookie restoration using supplied Google refresh tokens and geographically matched SOCKS5 proxies, enabling silent session hijacking and persistent access to web services.
read more β†’

Zero Trust: Bridging Authentication and Device Trust

πŸ”’ The perimeter model has broken down as workforces go hybrid, and many Zero Trust deployments miss a key link between identity and session authorization. Specops Device Trust argues that authentication must be contextualized with real-time device posture checks to prevent token theft and session hijacking. Binding identity to a verified device and continuous monitoring lets organizations enforce dynamic, low-friction policies that reduce risk.
read more β†’

Five Ways Chrome Enterprise Strengthens Browser Security

πŸ”’ Chrome Enterprise outlines five enhancements aimed at reinforcing browser security for organizations, addressing modern risks from session theft to malware-driven credential theft. Highlights include Device Bound Session Credentials to prevent session hijacking, cache encryption to protect data at rest, and App-bound encryption to block unauthorized apps from reading browser-stored secrets. Administrators also get tighter download controls and deeper integrations with partners such as Citrix and Okta to improve access decisions and incident response.
read more β†’

Critical CTEK Chargeportal Vulnerabilities and Risks

⚠️ Multiple authentication and session-management vulnerabilities in CTEK Chargeportal could allow remote attackers to impersonate charging stations, send unauthorized OCPP commands, or disrupt charging services. The highest-severity issue (CVE-2026-25192) affects WebSocket authentication and is rated CVSS 9.4 (Critical). Other flaws enable brute-force attempts, session hijacking, and exposure of station identifiers. CTEK plans to sunset Chargeportal in April 2026; operators should restrict network exposure, isolate control networks, and contact CTEK support for guidance.
read more β†’

Inside Tycoon2FA: Scale and AiTM Phishing Operations

πŸ”Ž Tycoon2FA emerged in August 2023 as a phishing-as-a-service platform that provided adversary-in-the-middle (AiTM) capabilities to relay authentication flows and capture session cookies. Its web-based admin panel centralized templates, redirects, hosting, CAPTCHA, and exfiltration controls while exposing real-time metrics. Fast-moving short-lived domains, Cloudflare hosting, and heavy obfuscation let low-skill operators run scalable campaigns against MFA-protected accounts worldwide.
read more β†’

Critical OCPP Backend Vulnerabilities in Everon Platform

πŸ”’ CISA reports multiple critical vulnerabilities in Everon OCPP Backends (api.everon.io) that permit unauthenticated access, session hijacking, credential exposure, and denial-of-service. The advisory details four CVEs, including a CVSS 3.1 score of 9.4 for missing authentication on WebSocket endpoints. Everon reportedly shut down the platform on December 1, 2025; CISA recommends isolating control networks, restricting Internet access, and using secure remote access methods.
read more β†’

Chargemap Charging Infrastructure Vulnerabilities Reported

πŸ”’ CISA reports multiple vulnerabilities in Chargemap's public charging infrastructure that could allow attackers to impersonate charging stations, hijack sessions, and disrupt services. The most severe issue (CVE-2026-25851) involves unauthenticated OCPP WebSocket endpoints and carries a CVSS 3.1 base score of 9.4. Chargemap did not respond to coordination; users should contact vendor support and reduce network exposure until fixes are available.
read more β†’

CloudCharge OCPP WebSocket Flaws Enable Station Impersonation

⚠️ CISA warns of multiple critical vulnerabilities in CloudCharge cloudcharge.se affecting OCPP WebSocket endpoints (four CVEs, highest CVSS 9.4). Exploits can enable station impersonation, session hijacking, credential exposure, and large-scale denial of service by suppressing or misrouting telemetry. CloudCharge did not respond to coordination requests; operators should apply network mitigations and restrict Internet exposure. CISA identifies Energy and Transportation sectors as at risk worldwide.
read more β†’