CAREER & HIRING ADVICE
Share it
Facebook
Twitter
LinkedIn
Email

Cookie Theft Is Now Bigger Business Than Password Theft

Website browser mockup representing session cookies and digital login risk

Multi-factor authentication put a spanner in the works for credential thieves. Since most accounts – or, at least, most of the accounts that have credit card details, medical information, or other sensitive data attached to them – are now surrounded by the thorny wall that is MFA, password theft can easily represent a lot of effort for very little reward. Yes, credential stuffing is getting easier than ever thanks to powerful automations that can run thousands of attempts for different accounts in very little time, but what benefit is that if access requires a physical device or biometric that the thief simply doesn’t have available to them?

But that doesn’t mean that the war is won. As with any counterattack from the cybersecurity industry, there’s always another counter-counterattack from the horde, and this one comes in the form of cookie theft. Infostealer malware capable of harvesting cookies, local storage, and cached data from unsuspecting sites is now on the rise.

If you have a layperson’s understanding of cookies, you might wonder what the big deal is. Browser session data, while useful to advertisers (as we all know by now) surely doesn’t pose as much scope for easy profit as a password to an account that contains credit card numbers or compromising information?

Why cookie theft?

If you’re asking this question, you probably have a limited understanding of what cookies actually are. They’re not just a crumb trail of what products you’re interested in, what brands you like, and what your browsing habits are.

Think about how you can open a website that you previously visited, say, last week. Last week, you created an account and placed an order. This week, upon opening the site, you’re still logged in. The convenience of skipping the login screen is made possible by your cookies.

Are you starting to see why this could be such a problem?

With stolen cookies, attackers can skip the login screen (and, by extension, MFA) and gain access to your account with relative ease. Infostealer malware doesn’t take long to take all the cookies from a device and post them to the darkweb, where they can be used for all sorts of nefarious purposes.

What’s the solution?

As with most forms of attack online, there’s no simple solution. First, we need to reframe our understanding of cookies so that we can treat them like the high-value credential they really are.

A session cookie enables you to refresh your email or browse a website without logging back in every single time you open a new page. If someone else takes possession of your session cookie, the trouble starts.

For users who log out or close the tab after a session, this isn’t such a worry. For businesses that automates tasks that require the script to log in and out of different browsers and platforms, however, the risk is far more pressing. Effective cookie management in browser automation is a vital practice to introduce into workflows, since automation that takes those session cookies for granted is going to leave a major vulnerability open to infostealer malware.

Share it
Facebook
Twitter
LinkedIn
Email

Categories

Related Posts

YOUR NEXT ENGINEERING OR IT JOB SEARCH STARTS HERE.

Don't miss out on your next career move. Work with Apollo Technical and we'll keep you in the loop about the best IT and engineering jobs out there — and we'll keep it between us.

HOW DO YOU HIRE FOR ENGINEERING AND IT?

Engineering and IT recruiting are competitive. It's easy to miss out on top talent to get crucial projects done. Work with Apollo Technical and we'll bring the best IT and Engineering talent right to you.