Skip to content
Knowledge base

Infostealers and session theft: why MFA isn't enough and how to protect yourself

In 2025, infostealers infected 11.1 million machines and produced 3.3 billion stolen credentials. By stealing cookies and session tokens, they bypass even MFA. We explain the mechanism and show how to defend.

Multi-factor authentication (MFA) is one of the most important safeguards — but it is not untouchable. An entire class of malware, infostealers, bypasses it without breaking it, simply by stealing what is created after a successful login: cookies and session tokens. In 2025, according to Recorded Future/Flashpoint, infostealers infected 11.1 million machines and produced 3.3 billion stolen credentials. This is one of the most underestimated vectors of the 2026 threat landscape.

This article explains what infostealers are, why they bypass MFA and how to realistically reduce this risk. It is a continuation of the token-theft thread we also describe in Device Code Phishing.

What an infostealer is

An infostealer is malware specialized in stealing data from an infected device. It is usually interested in:

  • passwords saved in the browser and in password managers,
  • cookies and session tokens (the key to this article),
  • cryptocurrency wallet data,
  • selected files and system data.

The stolen data, the “logs,” ends up on criminal markets, where it is sold in bulk. The most frequent infostealer of 2025 remained Lumma (LummaC2) — despite the May action in which Microsoft, Europol and the FBI seized about 2,300 domains linked to this family. The scale of the market means that the temporary takedown of one family is quickly replaced by others.

Why infostealers bypass MFA

This is the most important part. When you log in to an application and pass MFA, the server issues your browser a proof of successful authentication — a cookie or a session token. As long as it is valid, you don’t have to log in again.

It is precisely this proof that the infostealer steals. The attacker injects the stolen cookie/token into their own browser and becomes a “logged-in user” to the application — without a password and without a second factor, because the authentication step is already “ticked off.” This is session hijacking.

The bypass mechanism here is identical to that of Device Code Phishing: the attack targets neither the password nor MFA, but the token issued after them. That is why the mere presence of MFA is not enough — you also have to protect the session.

The problem of unmanaged devices (BYOD)

Infostealers most often land on devices outside IT’s control. According to Verizon DBIR 2025, 46% of infected devices with corporate credentials are unmanaged (BYOD). That’s a personal laptop with a saved login to corporate email, a home computer with access to SaaS — endpoints with no corporate EDR or policies.

The practical conclusion: as long as unmanaged devices have access to corporate resources, the infostealer attack surface remains open regardless of how well the corporate workstations are secured.

The infostealer as the first stage of a larger attack

Infostealers are rarely an end in themselves — more often they are a prelude. According to Verizon DBIR 2025, as many as 54% of ransomware victims had previously had their domains in infostealer logs, and 40% of those logs contained corporate email addresses. The chain is typical: infostealer infection → theft of credentials/session → sale of access to a broker → entry by a ransomware operator → encryption or leak. See what ransomware is and how to protect yourself and the broader 2026 cyber threat landscape.

How to defend

Defense works on three levels: don’t get infected, reduce the value of a stolen session, and quickly detect abuse.

1. Endpoint and hygiene

  • Deploy EDR/XDR on endpoints and keep updates current — this is the basic infection-detection barrier.
  • Limit saving passwords in the browser on unmanaged devices; promote password managers with strong protection.
  • Educate about infection vectors: malicious ads, fake tool sites (including fake AI tools), pirated software, attachments. Tie this to anti-phishing hygiene.

2. Reduce the value of a stolen session

  • Shorten token lifetimes for high-risk applications — the shorter the validity window, the lower the value of a stolen session.
  • Introduce binding the session to the device/context (token binding) where possible, so that a stolen token does not work from a foreign device.
  • Use Conditional Access requiring a compliant device — this limits the use of a stolen session to managed devices.
  • Get BYOD access in order — limit or segregate unmanaged devices’ access to corporate resources.

3. Detect session abuse

  • Monitor anomalies: “impossible travel,” unusual locations/IPs, parallel sessions, a change in the device fingerprint.
  • Monitor your own domains in infostealer logs — the free moje.cert.pl tool helps (domain scanning and attack-surface monitoring).
  • Prepare a procedure to quickly revoke sessions and rotate credentials after detecting an infection — a password reset alone does not invalidate an active stolen session.

Summary

Infostealers shift the center of gravity of defense from “do I have MFA” to “do I protect the session after MFA.” A stolen cookie or token lets an attacker act as a logged-in user, and in 2025 this vector fed more than half of ransomware attacks. An effective response combines endpoint protection, shortening token lifetimes and token binding, discipline toward BYOD devices and detection of session anomalies — and treating session theft as a real, not theoretical, risk.

The content above is educational. If you want to assess your company’s exposure to infostealers and session theft and deploy abuse detection, the nFlo team can help design and test appropriate safeguards.

Sources and reference materials

  • Recorded Future / Flashpoint — infostealer data 2025
  • Verizon Data Breach Investigations Report (DBIR) 2025
  • CERT Poland (NASK) — the moje.cert.pl tool; the action against the Lumma family (Microsoft/Europol/FBI)

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist