Cybersecurity News

Filters
Tag
Reset

Filtered by tag: session hijacking × Clear

Mirage2FA Phishing Kit Bypasses MFA to Hijack Microsoft 365 Sessions, Targeting 3,500+ Organizations

Matched: health

A phishing-as-a-service toolkit called Mirage2FA, linked to the group LinX Coders, has potentially compromised 4,532 Microsoft 365 accounts across 3,518 organizations in 94 countries, with 63.7% of victims in the US. The kit uses HTML, XHTML, and SVG attachments to deploy adversary-in-the-middle proxies that capture authenticated session cookies, bypassing MFA without dropping malware. Over half of 9,332 recorded compromise events involved cookie theft, making simple password resets insufficient for remediation.

AmnesiaStealer Gives Hackers Hidden Control of Logged-In Browsers on Macs

Matched: cryptocurrency

AmnesiaStealer is a new macOS malware spread via fake GitHub pages that trick users into running a Terminal command. Beyond stealing passwords, cookies, and keychain data, it can silently mirror an active browser session in a hidden Chromium instance, giving attackers real-time control of already-authenticated accounts. This makes MFA protections ineffective. A LaunchDaemon ensures persistence after the initial infection.