Session Hijacking Explained: Why Stolen Cookies Beat Your Password
A newly documented piece of malware called Abyssos has put a quiet attack technique back in the spotlight. As reported this week by GBHackers, Abyssos is a remote-access trojan that doesn’t bother cracking your password. It steals the session cookie your browser already holds and walks straight into your accounts. The technique is called session hijacking, and it’s worth understanding.
How it actually works
When you log in to Microsoft 365, your bank or a client portal and tick “keep me signed in,” the site hands your browser a session cookie so you’re not re-entering your password on every click. Malware like Abyssos copies those cookies off the machine. Loaded into an attacker’s browser, the cookie effectively says “this person is already signed in” — so the login screen, the password and the multi-factor prompt are all skipped.
Why it matters for Australian businesses
Here’s the uncomfortable part we see across the Sydney and Central West NSW businesses we manage: the accounts that get taken over usually aren’t the ones with weak passwords. They’re the ones where a session cookie was lifted off an unmanaged or unpatched laptop, so MFA never got a look-in. Multi-factor authentication is essential, but it isn’t a force field. If the device is compromised, the cookie sitting on it is compromised too.
What to do about it
- Run proper endpoint protection (EDR) on every device — it’s the layer that catches info-stealers before they harvest cookies.
- Actually sign out of sensitive apps instead of staying logged in for weeks on end.
- In Microsoft 365, turn on sign-in alerts and shorten session lifetimes so stolen cookies expire faster.
- Teach staff to be suspicious of “your session expired, log in again” pop-ups, a common way these attacks start.
Not sure if your devices would catch this?
We help Australian businesses lock down endpoints, tighten Microsoft 365 sign-in policies and train teams to spot the tricks. It’s the practical difference between MFA that holds and MFA that gets skipped.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
