Pass-the-cookie
Also called: cookie theft
Pass-the-cookie is an attack in which a stolen browser session cookie is loaded into the attacker's own browser to enter the victim's account. Because the cookie proves the user already signed in, the attacker skips the password and MFA prompts entirely. It is a form of session hijacking that often follows infostealer malware.
How it works
Malware on the victim's computer copies cookies from the browser's storage and sends them to the attacker, or a phishing proxy captures them at login. The attacker imports the cookies and opens the site, which accepts the session as genuine. The access lasts until the session expires, the user signs out everywhere or the site revokes it.
A real example
In October 2021 Google's Threat Analysis Group described a phishing campaign that used cookie theft malware against YouTube creators, and said many hijacked channels were rebranded for cryptocurrency scam live-streams.
Source: Phishing campaign targets YouTube creators with cookie theft malware — Google Threat Analysis Group, 2021-10-20
How to stop it
Bind sessions to the device that created them, keep session lifetimes short for sensitive apps, and re-check identity when a session suddenly appears from a new location or device.
Related terms
Sources
- Phishing campaign targets YouTube creators with cookie theft malware — Google Threat Analysis Group, 2021-10-20
Last reviewed Oct 2, 2026