Session hijacking
Session hijacking is taking over a user's authenticated session, usually by stealing the session token or cookie a site issues after login. With that token the attacker is treated as the signed-in user, without needing the password or passing MFA again, until the session expires or is revoked.
How it works
Attackers obtain session tokens from infostealer malware, phishing proxies, exposed log or troubleshooting files, or insecure networks. They load the token into their own browser or tool and send requests as the victim. Long session lifetimes and tokens that work from any device make the stolen session more useful.
A real example
The FBI, CISA and HHS advisory on ALPHV Blackcat said its affiliates used the open-source adversary-in-the-middle framework Evilginx2 to obtain MFA credentials, login credentials and session cookies.
Source: #StopRansomware: ALPHV Blackcat (AA23-353A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-12-19
How to stop it
Keep admin session lifetimes short, bind sessions to the device or network they started on, and revoke sessions when risk signals change. Strip tokens from files before sharing them.
Related terms
Threat actors that use it
- ALPHV Blackcat
Profile with government sources
Sources
- #StopRansomware: ALPHV Blackcat (AA23-353A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-12-19
Last reviewed Oct 2, 2026