DarkOwl and Verizon: Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks

DarkOwl and Verizon: Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks

Infostealer Malware Fuels Ransomware Surge by Bypassing MFA

Infostealer malware has emerged as a critical enabler of ransomware attacks, providing attackers with silent access to corporate networks by harvesting credentials, session cookies, and other sensitive data from infected devices. Unlike ransomware, which announces its presence, infostealers operate covertly, exfiltrating data to attacker-controlled servers without disrupting system functionality.

The stolen data compiled into "stealer logs" is aggregated and sold by initial access brokers to ransomware affiliates. The most dangerous component of these logs is active session cookies, which allow attackers to hijack authenticated sessions without triggering multi-factor authentication (MFA). By importing stolen cookies into their browsers, threat actors inherit the victim’s authenticated state, bypassing passwords and MFA entirely.

DarkOwl’s research highlights that session hijacking is one of several techniques used to defeat MFA, alongside push bombing and adversary-in-the-middle phishing. Verizon’s 2025 Data Breach Investigations Report found that 88% of web-application breaches involved stolen credentials, many sourced from infostealer logs reused in credential-stuffing attacks.

Underground marketplaces, including Telegram groups and searchable "Underground Clouds of Logs," have streamlined the trade of stolen credentials, enabling even low-skilled attackers to acquire bulk data. In June 2026, a single collection of stealer logs contained 124 million unique passwords, underscoring the scale of this threat.

Since stolen session tokens remain valid until revoked, organizations face persistent risks long after the initial infection. Incident responders recommend revoking active sessions before resetting passwords, as password changes alone fail to block attackers holding live tokens. With MFA adoption widespread, stolen session cookies have become the primary tool for ransomware affiliates to infiltrate enterprise networks undetected.

Source: https://gbhackers.com/hackers-stealer-logs-launch-ransomware-attacks/

Verizon cybersecurity rating report: https://www.rankiteo.com/company/verizon

DarkOwl cybersecurity rating report: https://www.rankiteo.com/company/one-world-labs

"id": "VERONE1784967835",
"linkid": "verizon, one-world-labs",
"type": "Cyber Attack",
"date": "6/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'type': 'Corporate networks'}],
 'attack_vector': ['Stolen credentials',
                   'Session hijacking via stolen cookies',
                   'Credential-stuffing attacks'],
 'data_breach': {'data_exfiltration': True,
                 'number_of_records_exposed': '124 million unique passwords '
                                              '(in a single collection)',
                 'personally_identifiable_information': True,
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, authenticated session '
                                        'data)',
                 'type_of_data_compromised': ['Credentials',
                                              'Session cookies',
                                              'Sensitive data']},
 'description': 'Infostealer malware has emerged as a critical enabler of '
                'ransomware attacks, providing attackers with silent access to '
                'corporate networks by harvesting credentials, session '
                'cookies, and other sensitive data from infected devices. The '
                "stolen data is compiled into 'stealer logs' and sold by "
                'initial access brokers to ransomware affiliates. Session '
                'hijacking via stolen cookies bypasses MFA, allowing attackers '
                'to inherit the victim’s authenticated state. This method, '
                'along with push bombing and adversary-in-the-middle phishing, '
                'is used to defeat MFA. Stolen session tokens remain valid '
                'until revoked, posing persistent risks to organizations.',
 'impact': {'data_compromised': 'Credentials, session cookies, sensitive data',
            'identity_theft_risk': 'High',
            'operational_impact': 'Persistent unauthorized access to networks',
            'systems_affected': 'Corporate networks, web applications'},
 'initial_access_broker': {'data_sold_on_dark_web': True,
                           'entry_point': 'Infected devices via infostealer '
                                          'malware'},
 'lessons_learned': 'Stolen session tokens remain valid until revoked, posing '
                    'persistent risks. Organizations must revoke active '
                    'sessions before resetting passwords to mitigate '
                    'unauthorized access.',
 'motivation': ['Financial gain', 'Data exfiltration', 'Network infiltration'],
 'post_incident_analysis': {'corrective_actions': ['Revoking active sessions '
                                                   'before password resets',
                                                   'Monitoring underground '
                                                   'marketplaces for stolen '
                                                   'data',
                                                   'Implementing MFA solutions '
                                                   'resistant to session '
                                                   'hijacking'],
                            'root_causes': ['Infostealer malware harvesting '
                                            'credentials and session cookies',
                                            'Underground trade of stolen data '
                                            'enabling ransomware affiliates',
                                            'Session hijacking via stolen '
                                            'cookies bypassing MFA']},
 'ransomware': {'data_exfiltration': True},
 'recommendations': ['Revoke active sessions before resetting passwords',
                     'Monitor for stolen credentials and session cookies on '
                     'underground marketplaces',
                     'Implement adaptive MFA solutions resistant to session '
                     'hijacking',
                     'Enhance monitoring for unauthorized access via stolen '
                     'session tokens'],
 'references': [{'source': 'DarkOwl Research'},
                {'source': 'Verizon 2025 Data Breach Investigations Report'}],
 'response': {'containment_measures': 'Revoking active sessions before '
                                      'resetting passwords'},
 'threat_actor': 'Initial access brokers, ransomware affiliates',
 'title': 'Infostealer Malware Fuels Ransomware Surge by Bypassing MFA',
 'type': 'Ransomware Enablement via Infostealer Malware',
 'vulnerability_exploited': 'Active session cookies (bypassing MFA)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.