HomeSecurityCookie-Bite Attack: How can hackers bypass MFA?

Cookie-Bite Attack: How can hackers bypass MFA?

A proof-of-concept (PoC) attack, known as “Cookie-Bite,” leverages a browser extension to intercept login cookies from the Azure Entra ID platform, aiming to bypass multi-factor authentication (MFA) and maintain unhindered access to cloud services such as Microsoft 365, Outlook, and Teams.

Cookie-Bite attack cookies Azure Entra

This technique was developed by cybersecurity researchers at Varonis, who presented a PoC method based on the use of a malicious and legitimate Chrome extension. Although cookie stealing is not a new practice, this particular technique stands out due to its discreet and persistent nature.

See also: Malicious VSCode extensions infect Windows with cryptominer

The attack is based on a malicious Chrome extension, which acts as an infostealer, specifically targeting two cookies: ESTAUTH and ESTSAUTHPERSISTENT, used by Microsoft's Azure Entra ID service.

• ESTAUTH: This cookie indicates that the user has successfully passed authentication, including MFA. It remains active as long as the browser is open, up to 24 hours.

• ESTSAUTPERSISTENT: This is a longer-lasting version of the cookie, remaining active for up to 90 days when the user selects "Stay signed in" or when the Azure KMSI policy is enabled.

The attack is particularly dangerous, as attackers can gain continued accounts a user's, even after they think they are logged out or protected by MFA.

It is worth noting that, although the “Cookie-Bite” attack extension was designed to target Microsoft login cookies, it could easily be modified to attack other popular services, such as Google, Okta, or AWS.

The malicious Chrome extension developed by Varonis tracks the user's movements in real time , detecting when they log in to Microsoft websites and observing browser tab updates based on specific URLs (such as login.microsoftonline.com).

When a connection is detected, the extension reads all relevant cookies and specifically filters out the two important tokens ESTAUTH and ESTSAUTHPERSISTENT. It then extracts the cookie JSON data and sends it to the attacker via a Google Form.

See also: VSCode extensions downloaded ransomware at an early stage

The Varonis team warned that when this extension was packaged into a CRX file and uploaded to VirusTotal (a malware detection platform), no well-known security provider identified it as malicious.

If attackers gain physical or remote access to a computer, they can create a PowerShell script, which will be set to run at Windows startup via Task Scheduler. This script automatically reinstalls the extension in Chrome in developer mode, keeping it active even after a reboot.

Cookie-Bite Attack: How can hackers bypass MFA?
Cookie-Bite Attack: How can hackers bypass MFA?

Once they have a stolen cookie in their hands, attackers can “load” it into the browser, using tools like Cookie-Editor (a legitimate Chrome extension). By inserting the cookie into the same Microsoft login domain and refreshing the page, Azure treats it as a normal, confirmed login, bypassing the MFA check entirely and granting full access as if it were the legitimate user.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Once attackers gain access, they can leverage Graph Explorer to discover users, roles, and devices, send messages, read conversations in Microsoft Teams, or even read and download emails via Outlook Web.

The attack can be further extended, allowing the attacker to escalate privileges, spread across the network, or perform unauthorized application registrations, using tools such as TokenSmith, ROADtools, and AADInternals.

Microsoft, during the researchers' demonstration of the attack, characterized the connection attempts as "atRisk" as they were made over a VPN. This highlights how important it is for organizations to monitor for suspicious or unusual connections as a key prevention measure.

For additional protection, it is recommended to implement Conditional Access Policies (CAP), which can restrict connections only to specific IP addresses or approved devices.

See also: New Polymorphic attack mimics Chrome extensions

When it comes to Chrome extensions, it is recommended to use Chrome management policies (Chrome ADMX) to only allow predefined, approved extensions and disable developer mode completely so that users cannot install unverified extensions.

Also, to protect cookies and the session, it is recommended to use short session timeouts , avoid using the “Stay logged in” option , and enable the setting that prevents JavaScript from accessing session cookies.

Finally, anti-malware and anti-spyware checks should be performed regularly and all programs and operating systems should be updated to address potential security gaps.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS