Avatier

Session or token theft

Session hijacking

Session hijacking is taking over a user's authenticated session, usually by stealing the session token or cookie a site issues after login. With that token the attacker is treated as the signed-in user, without needing the password or passing MFA again, until the session expires or is revoked.

How it works

Attackers obtain session tokens from infostealer malware, phishing proxies, exposed log or troubleshooting files, or insecure networks. They load the token into their own browser or tool and send requests as the victim. Long session lifetimes and tokens that work from any device make the stolen session more useful.

A real example

The FBI, CISA and HHS advisory on ALPHV Blackcat said its affiliates used the open-source adversary-in-the-middle framework Evilginx2 to obtain MFA credentials, login credentials and session cookies.

Source: #StopRansomware: ALPHV Blackcat (AA23-353A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-12-19

How to stop it

Keep admin session lifetimes short, bind sessions to the device or network they started on, and revoke sessions when risk signals change. Strip tokens from files before sharing them.

Related terms

Threat actors that use it

Sources

  1. #StopRansomware: ALPHV Blackcat (AA23-353A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-12-19

Last reviewed Oct 2, 2026