Stolen session cookies give hackers full account access for under a thousand dollars per month without raising alerts

Stolen session cookies give hackers full account access for under a thousand dollars per month without raising alerts


  • Storm enables session hijacking that bypasses passwords and multi-factor authentication
  • Attackers can restore stolen sessions remotely without triggering standard security alerts
  • Malware operates server-side to process encrypted browser credentials for stealthy exploitation

A new strain of infostealer malware dubbed Storm is changing how account compromise works, experts have warned.

New findings from Varonis Threat Labs have outlined how this strain moves away from passwords and focuses on session cookies that keep users logged in.

Leave a Reply

Your email address will not be published. Required fields are marked *