In brief: Infostealers are increasingly harvesting active session tokens, which attackers use to bypass MFA and move toward Active Directory.
In addition to passwords, infostealer malware is increasingly extracting active session tokens from browsers. With a valid token, attackers can completely bypass multi-factor authentication and slip directly into existing sessions.
Infostealers specialize in harvesting credentials stored on infected systems. In addition to classic credentials such as usernames and passwords, current variants of this malware also extract active session tokens from browsers and applications. Such a token confirms to a service that a session has already been successfully authenticated — including a previously completed multi-factor login.
For attackers, a valid, stolen session token means they can impersonate an already logged-in user without having to enter a password or second factor themselves. The MFA check is not broken in this process, but simply bypassed, since it has already taken place. From this initial access point, attackers can move laterally through the environment, aiming to escalate privileges and ultimately reach Active Directory — the central instance for identity and privilege management in many corporate networks.
This shifts the focus of classic identity protection for CISOs: MFA alone no longer provides reliable protection if the underlying session can be compromised. The key question becomes how quickly leaked credentials and tokens can be detected and invalidated before they can be used in an attack.
Exposure management is cited as a countermeasure in this context, checking leaked credentials for validity in near real time, detecting possible MFA bypasses, and assessing the associated permissions. This can shorten the window in which stolen tokens are actually usable for access.
Source: www.security-insider.de · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.