Blindfy — Digital Protection

Infostealers and session cookie theft: the criminal's passwordless login

The 16 billion credentials already leaked and how malware like RedLine, Vidar and Lumma bypasses passwords and 2FA.

Audience: SaaS Platforms · Risk level: CRITICAL

Blindfy Intelligence Unit · Technical review by Blindfy

Scenario

An employee reports that his corporate account was accessed from another country. The password is intact, 2FA is active, and yet a login succeeded. The reason: an infostealer running on his personal laptop exfiltrated the browser's session cookies, and the criminal entered the SaaS without needing a password.

How the scam works

Malware like RedLine, Vidar and Lumma spreads via cracks, plugins, attachments and fake installers. It collects saved passwords, crypto wallets and — most valuable — active session cookies. Those cookies are sold in forums for a few dollars and allow logging in directly as the user without triggering any 2FA. Recent surveys point to more than 16 billion leaked credentials in circulation.

Common mistake

Thinking MFA is the final answer. MFA protects the login. Session cookies skip the login entirely.

Impact

Access to admin panels, exfiltration of customer data, source code exposure, cloud account hijacking and massive costs in consumed resources. For SaaS, trust in the product is shaken for the long term.

What works

Blindfy monitors marketplaces and Telegram channels selling corporate cookies and credentials, provides incident response with mass session invalidation and structures a browser hardening policy for administrative access.

Protection checklist

  • Reduce session TTL for administrative systems
  • Require continuous reauthentication for sensitive actions
  • Bind sessions to a device fingerprint (device binding)
  • Block non-corporate browsers on critical panels
  • Monitor cookie and credential marketplaces
  • Deploy EDR on endpoints with administrative access
  • Adopt Zero Trust for every integration

Editorial sources

Strong passwords and MFA aren't enough when the session has already been stolen. Modern defense is continuously revalidated.

← All risk analyses · Blindfy initial assessment