Connect with us

Tech News

Unstoppable Access: How Stolen Session Cookies Can Bypass IT Security Measures and Reach Corporate Gmail

Published

on

Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

Infostealers Hijack Claude Accounts Through Session Cookie Replay

Recently, there have been reports of infostealers hijacking Claude accounts by replaying stolen session cookies into paid accounts without the need for two-factor authentication. This method allows the attackers to bypass the security measures put in place by the accounts.

The affected accounts were self-serve, card-billed accounts that were not governed by any corporate identity provider or admin console. The attackers were able to replay the stolen session cookies, bypassing single sign-on (SSO) as effectively as they bypassed two-factor authentication. While SSO offers revocation and visibility, it does not prevent such attacks.

Upon discovering the campaign, the company responsible for Claude sent notification emails to affected users, identifying six families of stealers involved in the attack. They signed the affected accounts out, removed saved payment methods, and refunded any unauthorized charges.

Although the immediate impact was limited to usage loss, the potential exposure was significant. The compromised sessions could have granted access to sensitive information that was not protected by enterprise-controlled identities.

According to reports, the attackers used common infostealer malware such as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic Stealer on a few Macs. These malware variants are designed to steal browser login cookies and saved passwords, allowing the attackers to access user sessions.

The Significance of Session Cookies

A session cookie serves as proof that a login has occurred. In this attack chain, the stolen session cookies enable attackers to access everything that the legitimate user could reach within the account.

See also  Itron's Internal IT Network Breach Revealed: A Closer Look at the American Utility Firm's Security Incident

By replaying these cookies, the attackers can trick the server into believing that the session is legitimate, thus gaining unauthorized access to the account.

While the company was able to mitigate the attack by signing the accounts out, the risk of exposure to sensitive data remains.

Protecting Against Future Attacks

To prevent similar attacks in the future, users are advised to be cautious of phishing attempts disguised as notifications from the company. It is essential to verify the authenticity of such communications to avoid falling victim to copycat phishing schemes.

Furthermore, organizations should consider implementing additional security measures such as device-bound session credentials to prevent account takeovers and unauthorized access to sensitive information.

By staying vigilant and adopting best practices in cybersecurity, users and organizations can protect themselves against the threat of infostealer attacks and safeguard their valuable data.

Trending