Hackers Use Cookies to Bypass two factor authentication
Abservetech
Aug 22, 2022 · 2 min read ·13k

Cookie theft is nothing but an attack that lets hackers bypass logins and gain access to personal databases.
According to Sophos, Cookie Theft is one of the latest trends in cybercrime. Hackers have found a way to bypass cookies attached to logins and copy them to hijack active or recent web sessions of programs that are not usually updated.
Security advice for organizations is to move their most sensitive information to cloud services or use Multi-Factor Authentication (MFA).
These hackers can exploit various online tools and services, including browsers, web applications and services, malware-infected emails, and ZIP files. The most insidious aspect of this hack is that cookies are so widely used that even with security protocols in place, they could still allow malicious users to gain access to a computer.
The emote botnet is one of a kind of cookie-stealing malware that targets data like login credentials and payment card data stored in the Google Chrome browser.
While browsing is involved in encryption and Multi-Factor Authentication, Sophos notes that Emote botnet can circumvent these protections. The login credentials of an Electronic Arts game developer ended up on a marketplace called Genesis, which is said to have been purchased by a blackmail group.
According to a report by TorrentFreak, cybercriminals can often purchase stolen cookie data, login credentials, and more in the underground market.
This group was able to clone EA employee credentials and eventually gained access to the company’s network, stealing 780 gigabytes of data. They gathered details about the game’s source code and the graphics engine they used to blackmail the company.
Also, Lapsus$ hacked Nvidia’s database in March. The breach reportedly exposed the credentials of 70,000 employees, along with 1 TB of company data, including terms, drivers, and firmware details.
However, it is unclear whether the hack was due to Cookie Theft. Hackers can use this to mislead users into downloading malware or sharing sensitive information.
When dealing with software-as-a-service products such as Amazon Web Services (AWS) or Slack other Cookie Theft opportunities can be found.
These services always run open, which means their cookies never expire because their protocols are secure. Reauthentication is required to log in to Facebook, Google, Twitter, or other major US websites that use cookies to access their services.
Users may also require to periodically delete their cookies to maintain the internet service provider’s (ISP) network infrastructure.
Similar Blogs:
How To Install Android 13 On Google Pixel
Twitter Is DOWN For Thousands Of Users, Claims Down Detector
To Connect With Us:
WhatsApp: +91 9222 47 9222
Email ID: support@abservetech.com
Abservetech
Building ready-to-launch clone scripts and custom apps for entrepreneurs worldwide since 2013.
Have a project in mind?
Talk to our team about turning this idea into a ready-to-launch product.
Get in touch
Balakanna - COO
I believe every idea has the power to create impact when it's backed with the right strategy and strong execution. Through our blogs, we share real insights, helpful tips, and proven solutions that come from experience. Hope you find something valuable here that helps you move forward.
Related articles
View all
Latest TrendsUnveiling iOS 17: Exciting New Features to Delight Apple Users
Coming months of Expectation, iOS 17 is now official. There were more features in iOS 16 but the upcoming iOS 17 includes the most advanced features. Here let us see about iOS 17 – the most requested
Read article
Latest TrendsHow to watch the first public demo of ChatGPT-4
OpenAI, with the release of a new version of its AI, has created quite a buzz, more so among AI enthusiasts. Recently, even as the OpenAI president and co-founder Greg Brockman gave a product tour, ex
Read article
Latest TrendsHow to watch the FIFA world cup 2022 for free in India?
The football frenzy has taken over! The 22nd edition of FIFA world cup 2022 kicked off on 20 November, with Qatar hosting the game for the first time. A total of 32 teams are contesting in the game. T
Read article