Infostealers can make standard MFA ineffective by stealing an authenticated session cookie after a user completes sign-in. An attacker can replay the stolen session instead of entering the password and MFA code again. The authenticated access may then be validated, sold by an Initial Access Broker, and used by a ransomware affiliate.
ProArch SOC is observing that Infostealers are bypassing MFA and providing ransomware affiliates with direct access to corporate environments.
Infostealer campaigns have increased significantly across client environments, and they are especially dangerous because the damage is often done before an infection is detected. Infostealers such as Lumma Stealer do not encrypt files or create obvious disruption.
Instead, they extract credentials and session cookies from a device within seconds, send the data to a criminal marketplace, and exit. Another actor—often a ransomware affiliate—then buys that access and enters through a trusted account.
The malware is lightweight and fast. Its sole purpose is to collect valuable data from a device and leave before anyone notices. It typically targets:
Session-cookie theft can make standard MFA ineffective in this scenario.
After you sign in with a password and MFA code, your browser receives a session cookie confirming that authentication has already occurred.
Lumma Stealer can steal and replay that cookie. The attacker does not need the password or MFA code because the cookie serves as proof of an authenticated session.
The sequence is simple: steal first, sell second, encrypt third.
Lumma Stealer (LummaC2) is currently a dominant infostealer family. It operates as malware as a service (MaaS) and has a rapid update cycle.
Microsoft and law enforcement took down roughly 2,300 of its command-and-control domains in May 2025, but the infrastructure was rebuilt within days. For persistence after infection, it places files in C:\ProgramData\app_config\ and creates a scheduled task that survives reboots.
ProArch’s 24/7 SOC monitors identities, endpoints, cloud environments, and networks to detect infostealer activity, stolen-session abuse, and related threats early.
Our analysts investigate alerts, hunt for indicators of compromise, contain threats, and coordinate rapid incident response before attackers can expand access or deploy ransomware.
| Technique | ID |
| Phishing: Spearphishing Link | T1566.002 |
| User Execution | T1204 |
| Signed Binary Proxy Execution (mshta.exe) | T1218.005 |
| Credentials from Web Browsers | T1555.003 |
| Steal Web Session Cookie | T1539 |
| Steal Application Access Token | T1528 |
| Obfuscated Files or Information | T1027 |
| Exfiltration Over C2 Channel | T1041 |
| Boot/Logon AutoStart – Registry Run Keys | T1547.001 |
Attacker infrastructure — Storm-2561 / Hyrax campaign:
Downstream Qilin C2 beaconing indicator (post-access):
If this last indicator appears, credential theft has likely already occurred and a ransomware affiliate may already have access.
One statistic stands out: stolen passwords and session cookies appeared in 86% of breaches in 2025. This is not a niche attack vector; it is a dominant one.
In an MSSP environment, the blast radius differs from that of a single-organization breach. A compromised technician account with VPN or RMM access may expose every client environment it can reach.
Microsoft Entra ID credentials appeared in 79% of analyzed corporate infostealer logs. If users authenticate to client environments through Entra ID, those accounts become prime targets. Standard TOTP-based MFA does not prevent the replay of a stolen session cookie because authentication has already occurred.
Another important factor is the delay between credential theft and ransomware deployment. IBM found that the average supply-chain-originated breach takes 267 days to detect.
Credentials stolen today may remain on a marketplace for months before an attacker buys and uses them. Proactive dark-web monitoring can help identify exposure before the access is exploited.