Observed Signal · Jul 6, 2026 · Security Analysis · Source: DEV Community · Impact: 3/5 · Sentiment: Negative

Session Hijacking: Cookie Theft Bypasses Two-Factor Authentication

Executive Signal Summary

The article explains session hijacking by cookie/theft of session tokens as a rapidly growing identity attack in 2026. Infostealer malware (e.g., RedLine, Raccoon, Lumma, Vidar) exfiltrates entire browser cookie stores and related credentials; those datasets—called “stealer logs”—appear on Telegram channels and dark‑web marketplaces. SpyCloud reports a 58% rise in infostealer infections and over 2.1 billion stolen cookie records. Google’s Threat Analysis Group says session token theft now causes more account takeovers than phishing, and Microsoft confirmed AiTM phishing kits plus session token theft drove a wave of enterprise compromises in early 2026. Because stolen cookies represent already-authenticated sessions, two‑factor authentication often cannot stop these attacks. Recommended protections include patching devices, using antivirus, logging out of sessions, clearing cookies, avoiding public Wi‑Fi or using a VPN, and adopting device‑bound or token‑binding session designs.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Rising session token theft undermines MFA and authenticated-session models, posing material risk to identity management, user trust, and any advertising or measurement systems that rely on stable user authentication.

SIGNAL RADAR

Track Google Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • SpyCloud reported infostealer malware infections grew 58% in the past year and cited over 2.1 billion stolen cookie records on underground marketplaces.
  • Google's Threat Analysis Group reported session token theft now accounts for more account takeovers than traditional phishing.
  • Microsoft confirmed in early 2026 that adversary-in-the-middle (AiTM) phishing kits combined with session token theft caused a significant wave of enterprise account compromises.
  • Infostealer malware examples include RedLine, Raccoon, Lumma, and Vidar; these tools extract browser cookie stores, saved passwords, autofill data, and cryptocurrency wallets.
  • Stolen datasets called 'stealer logs' are typically sold via Telegram channels and dark‑web marketplaces within 24–48 hours, often priced at $5–$30 per victim.

Connected Companies & Entities

3 Entities mapped

“Google's Threat Analysis Group reported that session token theft now accounts for more account takeovers than traditional phishing....”

“Microsoft confirmed in early 2026 that adversary-in-the-middle (AiTM) phishing kits combined with session token theft were responsible for a...”

“These stolen datasets, called "stealer logs," appear on Telegram channels and dark web marketplaces within 24 to 48 hours, often priced at j...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jul 6, 2026
Original Coverage Title: “Session Hijacking: How Cookie Theft Bypasses Your Two-Factor Authentication and How to Protect Yourself”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

IdentityJul 28, 2026

Public Wi‑Fi DNS Poisoning Hijacks Microsoft 365 Sessions

Security researchers report a campaign that compromises public Wi‑Fi gateway management interfaces (e.g., in hotels, conference centers) to forge DNS responses and WPAD proxy settings, redirecting users to fake Microsoft sign‑in pages. Attackers exploit the OAuth device‑code flow (Microsoft Entra ID) and WPAD to obtain MFA‑authenticated tokens and access Microsoft 365 sessions without installing malware on victims' devices. Activity has been observed since June 2026 in the US, India, and Saudi Arabia. Detection techniques include monitoring for IOC IPs/domains, PAC/WPAD downloads (WinHttpAutoProxySvc), device‑code sign‑ins, and unusual post‑MFA access from unknown IPs/locations. Primary coverage cites SecurityWeek and a detailed ReliaQuest threat spotlight as sources.

Read assessment
IdentityMay 21, 2026

OAuth Tunnel Trap: Preventing Subdomain Hijacking

A technical advisory from the InstaTunnel engineering team describes the "OAuth Subdomain Trap": attackers squatting freed ephemeral localhost tunnel subdomains (ngrok, Localtunnel, Cloudflare Tunnels, etc.) to receive OAuth authorization codes that remain whitelisted in identity provider consoles. The post explains attack stages (reconnaissance, subdomain squatting, code interception, token exchange), documents real-world incidents (Microsoft OAuth redirection abuse, JFrog's CVE-2025-6514), and highlights increased risk from AI agents and CI/CD preview environments. Recommended mitigations include using persistent custom subdomains under organizational control, mandating PKCE and strict state validation, enforcing edge (Zero Trust) authentication on tunnels, automating redirect_uri hygiene, and updating mcp-remote to v0.1.16 with HTTPS-only MCP connections.

Read assessment
SecuritySep 8, 2026

Hackers steal Claude tokens from subscribers via infostealer malware

Anthropic Claude users are facing unauthorized token consumption, with hackers using info-stealer malware to steal active login sessions and bypass passwords and MFA. Independent AI consultant Grant De Swardt saw his Claude Max account consume tokens while idle, and despite disabling connected services, usage continued. Anthropic locked his account, reset sessions, and invalidated tokens issued to Claude Code. Other users reported similar issues, including unauthorized upgrades to paid tiers without consent. Anthropic confirmed the attacker method and advised users to terminate sessions, change passwords, enable MFA, scan for malware, review payment details, and document unusual usage. However, without detailed usage reports, detecting abuse is difficult. The incident highlights growing security and trust concerns for AI subscription services, prompting some users to consider alternatives like Cursor.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.