How Are Infostealers Bypassing MFA and Enabling Ransomware Attacks?

August 17, 2026

By: Sai Rishi Kumar Bommakanti

Security Analyst

Quick Answer

Infostealers can make standard MFA ineffective by stealing an authenticated session cookie after a user completes sign-in. An attacker can replay the stolen session instead of entering the password and MFA code again. The authenticated access may then be validated, sold by an Initial Access Broker, and used by a ransomware affiliate.

ProArch SOC is observing that Infostealers are bypassing MFA and providing ransomware affiliates with direct access to corporate environments.

How Do Infostealers Turn Stolen Sessions into Ransomware Access?

Infostealer campaigns have increased significantly across client environments, and they are especially dangerous because the damage is often done before an infection is detected. Infostealers such as Lumma Stealer do not encrypt files or create obvious disruption.

Instead, they extract credentials and session cookies from a device within seconds, send the data to a criminal marketplace, and exit. Another actor—often a ransomware affiliate—then buys that access and enters through a trusted account.

How Does the Infostealer-to-Ransomware Attack Chain Work?

The malware is lightweight and fast. Its sole purpose is to collect valuable data from a device and leave before anyone notices. It typically targets:

  • Saved browser passwords pulled from Chromium’s local Login Data SQLite database
  • Active session cookies — and this is the important one
  • VPN configuration files and stored credentials
  • SSO and identity provider tokens
  • Crypto wallets, autofill data, anything with value

Session-cookie theft can make standard MFA ineffective in this scenario.

After you sign in with a password and MFA code, your browser receives a session cookie confirming that authentication has already occurred.

Lumma Stealer can steal and replay that cookie. The attacker does not need the password or MFA code because the cookie serves as proof of an authenticated session.

What happens after an Infostealer steals corporate credentials?

  • The stolen data—known as a stealer log—is packaged and listed on underground marketplaces within hours.
  • Initial Access Brokers use automated tools to scan millions of logs for corporate VPN portals, SSO consoles, AD FS, and Microsoft Entra ID credentials.
  • When they find a working corporate login, they validate it, grade it by company size and access level, and sell it.
  • Ransomware affiliates can then buy validated access and bypass the initial-access stage entirely.

The sequence is simple: steal first, sell second, encrypt third.

Why is Lumma Stealer a Major Infostealer threat?

Lumma Stealer (LummaC2) is currently a dominant infostealer family. It operates as malware as a service (MaaS) and has a rapid update cycle.

Microsoft and law enforcement took down roughly 2,300 of its command-and-control domains in May 2025, but the infrastructure was rebuilt within days. For persistence after infection, it places files in C:\ProgramData\app_config\ and creates a scheduled task that survives reboots.

How Can ProArch SOC Help?

ProArch’s 24/7 SOC monitors identities, endpoints, cloud environments, and networks to detect infostealer activity, stolen-session abuse, and related threats early.

Our analysts investigate alerts, hunt for indicators of compromise, contain threats, and coordinate rapid incident response before attackers can expand access or deploy ransomware.

Which MITRE ATT&CK techniques map to Infostealer and MFA Bypass activity?
Technique ID
Phishing: Spearphishing Link T1566.002
User Execution T1204
Signed Binary Proxy Execution (mshta.exe) T1218.005
Credentials from Web Browsers T1555.003
Steal Web Session Cookie T1539
Steal Application Access Token T1528
Obfuscated Files or Information T1027
Exfiltration Over C2 Channel T1041
Boot/Logon AutoStart – Registry Run Keys T1547.001
Which Infostealer and Ransomware indicators should security teams hunt for?

Attacker infrastructure — Storm-2561 / Hyrax campaign:

  • C2: 194.76.226[.]93:8080
  • Defender signature: Trojan:Win32/Malgent
  • Lumma persistence path: C:\ProgramData\app_config\

Downstream Qilin C2 beaconing indicator (post-access):

  • Outbound connections to cloudflariz[.]com every ~10 minutes (±1–3 min jitter)

If this last indicator appears, credential theft has likely already occurred and a ransomware affiliate may already have access.

Why Do Infostealers Create Greater Risk for MSSPs?

One statistic stands out: stolen passwords and session cookies appeared in 86% of breaches in 2025. This is not a niche attack vector; it is a dominant one.

In an MSSP environment, the blast radius differs from that of a single-organization breach. A compromised technician account with VPN or RMM access may expose every client environment it can reach.

Microsoft Entra ID credentials appeared in 79% of analyzed corporate infostealer logs. If users authenticate to client environments through Entra ID, those accounts become prime targets. Standard TOTP-based MFA does not prevent the replay of a stolen session cookie because authentication has already occurred.

Another important factor is the delay between credential theft and ransomware deployment. IBM found that the average supply-chain-originated breach takes 267 days to detect.

Credentials stolen today may remain on a marketplace for months before an attacker buys and uses them. Proactive dark-web monitoring can help identify exposure before the access is exploited.

How Can Organizations Reduce Infostealer and Session-Theft Risk?

  • Upgrade to phishing-resistant MFA methodsUse FIDO2 hardware keys or certificate-based authentication for systems that provide access to VPNs, SSO, or administrative consoles. Standard TOTP is not sufficient against session-cookie replay.
  • Enable Continuous Access Evaluation (CAE) in Microsoft Entra ID – CAE forces token revalidation when context changes, such as a new IP address, unmanaged device, or policy update. A stolen session cookie replayed from an unexpected location should trigger reauthentication rather than receive uninterrupted access.
  • Hunt for persistence paths now – Alert on scheduled-task creation and new binaries in C:\ProgramData\, %TEMP%, or %AppData%. Cross-reference these events with processes launched by mshta.exe, powershell.exe, or wscript.exe from user-interactive applications such as browsers, email clients, or PDF readers.
  • Block user-initiated execution of mshta.exe – This legitimate Windows binary is abused in ClickFix attacks as a proxy execution method (T1218.005). If your environment has no legitimate need for this behavior, block it and create an alert rule.
  • Add the Hyrax C2 indicators to your firewall and SIEM – Block 194.76.226[.]93 on port 8080. Add cloudflariz[.]com to the DNS blocklist, and create a Microsoft Sentinel or Splunk alert for outbound queries to that domain.
  • Monitor dark-web exposure for client domains – Credentials in stealer logs are a leading indicator of an attack. By the time a login anomaly appears in the SIEM, the log may already have been sold.

Cyber threats never sleep neither do we. ProArch SOC protects you 24/7.

Explore ProArch SOC Services