Web Session Cookie

T1550.004

Sub-technique of T1550 Use Alternate Authentication Material.View on attack.mitre.org

About this technique

Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols since the session is already authenticated.

Authentication cookies are commonly used in web applications, including cloud-based services, after a user has authenticated to the service so credentials are not passed and re-authentication does not need to occur as frequently. Cookies are often valid for an extended period of time, even if the web application is not actively used. After the cookie is obtained through Steal Web Session Cookie or Web Cookies, the adversary may then import the cookie into a browser they control and is then able to use the site or application as the user for as long as the session cookie is active. Once logged into the site, an adversary can access sensitive information, read email, or perform actions that the victim account has permissions to perform.

There have been examples of malware targeting session cookies to bypass multi-factor authentication systems.

Detection rules1

Rules on DetectionCode tagged with T1550.004.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk1

RuleTypeRiskData source
Okta Multiple Failed Requests to Access ApplicationsHuntingNULLOkta

Groups1

Software0

None recorded.

Campaigns1

Procedure examples2

Groups1

Used byProcedure example
GroupStar Blizzard

Star Blizzard has bypassed multi-factor authentication on victim email accounts by using session cookies stolen using EvilGinx.

Campaigns1

Used byProcedure example
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used stolen cookies to access cloud resources and a forged `duo-sid` cookie to bypass MFA set on an email account.

References2

  1. Pass The Cookie Open source
    Rehberger, J. (2018, December). Pivot to the Cloud using Pass the Cookie. Retrieved April 5, 2019.
  2. Unit 42 Mac Crypto Cookies January 2019 Open source
    Chen, Y., Hu, W., Xu, Z., et. al. (2019, January 31). Mac Malware Steals Cryptocurrency Exchanges’ Cookies. Retrieved October 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.