Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Close-up of a person using a laptop — endpoint security and EDR for Sydney businesses

Session Hijacking Explained: Why Stolen Cookies Beat Your Password

A newly documented piece of malware called Abyssos has put a quiet attack technique back in the spotlight. As reported this week by GBHackers, Abyssos is a remote-access trojan that doesn’t bother cracking your password. It steals the session cookie your browser already holds and walks straight into your accounts. The technique is called session hijacking, and it’s worth understanding.

Session hijacking, in plain English: stealing the small file (a “session cookie” or token) your browser uses to stay logged in, so an attacker can impersonate you without ever needing your password or your MFA code.

How it actually works

When you log in to Microsoft 365, your bank or a client portal and tick “keep me signed in,” the site hands your browser a session cookie so you’re not re-entering your password on every click. Malware like Abyssos copies those cookies off the machine. Loaded into an attacker’s browser, the cookie effectively says “this person is already signed in” — so the login screen, the password and the multi-factor prompt are all skipped.

Why it matters for Australian businesses

Here’s the uncomfortable part we see across the Sydney and Central West NSW businesses we manage: the accounts that get taken over usually aren’t the ones with weak passwords. They’re the ones where a session cookie was lifted off an unmanaged or unpatched laptop, so MFA never got a look-in. Multi-factor authentication is essential, but it isn’t a force field. If the device is compromised, the cookie sitting on it is compromised too.

What to do about it

  • Run proper endpoint protection (EDR) on every device — it’s the layer that catches info-stealers before they harvest cookies.
  • Actually sign out of sensitive apps instead of staying logged in for weeks on end.
  • In Microsoft 365, turn on sign-in alerts and shorten session lifetimes so stolen cookies expire faster.
  • Teach staff to be suspicious of “your session expired, log in again” pop-ups, a common way these attacks start.

Not sure if your devices would catch this?

We help Australian businesses lock down endpoints, tighten Microsoft 365 sign-in policies and train teams to spot the tricks. It’s the practical difference between MFA that holds and MFA that gets skipped.

Written by Caleb Attard, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality and not-for-profit sectors from its Brookvale base, and across Central West NSW.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →