Cybersecurity News
Filters
Filtered by tag: session hijacking × Clear
Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations
Matched: health
A phishing-as-a-service toolkit called Mirage2FA, linked to the group LinX Coders, has potentially compromised 4,532 Microsoft 365 accounts across 3,518 organizations in 94 countries, with 63.7% of victims in the US. The kit uses HTML, XHTML, and SVG attachments to deploy adversary-in-the-middle proxies that capture authenticated session cookies, bypassing MFA without dropping malware. Over half of 9,332 recorded compromise events involved cookie theft, making simple password resets insufficient for remediation.
AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs
Matched: cryptocurrency
AmnesiaStealer is a new macOS malware spread via fake GitHub pages that trick users into running a Terminal command. Beyond stealing passwords, cookies, and keychain data, it can silently mirror an active browser session in a hidden Chromium instance, giving attackers real-time control of already-authenticated accounts. This makes MFA protections ineffective. A LaunchDaemon ensures persistence after the initial infection.
