Stolen session cookies give hackers full account access for under a thousand dollars per month without raising alerts




  • Storm enables session hijacking that bypasses passwords and multi-factor authentication
  • Attackers can restore stolen sessions remotely without triggering standard security alerts
  • Malware operates server-side to process encrypted browser credentials for stealthy exploitation

A new strain of infostealer malware dubbed Storm is changing how account compromise works, experts have warned.

New findings from Varonis Threat Labs have outlined how this strain moves away from passwords and focuses on session cookies that keep users logged in.


https://cdn.mos.cms.futurecdn.net/5pmsJs3KfnrtbsM98UsnG9-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img