AILINCOM logo AILINCOM
Account Theft: Why Antivirus and 2FA Aren't Enough
Cover generated by AI
Crius

Crius

Aug 10, 2026
Основная категория
Digital technologies and IT · Cybersecurity
Дополнительные
Technologies and engineering · Cybersecurity

Account Theft: Why Antivirus and 2FA Aren't Enough

Account Theft: Why Antivirus and 2FA Aren't Enough

Even with active two-factor authentication and antivirus protection, attackers can gain access to accounts by stealing session cookies. This article explains how such attacks work, discusses modern protection methods, and offers practical security recommendations.

CriusAccount Theft: Why Antivirus and 2FA Aren't Enough

Session Hijacking Mechanism

Even after removing malicious software from a user's device with antivirus tools, spam may continue to be sent from their Google account, and unknown devices may appear in the list of connected devices. Two-factor authentication often remains enabled. This situation is caused by session hijacking—gaining access to an already active user session. In such cases, the attacker does not need to know the password or the second authentication factor; it is enough to obtain a special file—a session cookie—that the browser saves after login to enable automatic authorization during subsequent visits.

How Cookie Theft Happens

Most often, the attack begins when an infostealer program, designed to collect account credentials, infiltrates the device. This can happen through cracked software, fake installers, or malicious attachments. Once installed, the infostealer reads the browser's cookie files. The attacker then imports the stolen cookie into their own browser and gains access to the service without needing to re-authenticate.

According to the Global Threat Intelligence Report for 2025, over 11.1 million devices were infected with infostealers, and 3.3 billion credentials and cloud tokens were stolen. Session cookies are not included in this count.

Features and Limitations of Two-Factor Authentication

Two-factor authentication verifies the user only at login. After successful verification, a cookie is created to confirm authentication. If an attacker obtains this cookie, no further verification is required. Even advanced security programs, such as Google’s Advanced Protection Program, do not change this mechanism. If the user does not log out, the security key may not be requested again.

Measures Taken by Browsers

Since July 2024, Chrome for Windows (starting with version 127) encrypts cookies using App-Bound Encryption and ties the key to the application. However, malware with elevated privileges can bypass this protection, making theft more difficult but not impossible.

A more effective technology is Device Bound Session Credentials (DBSC), where the browser generates a key pair and the private key is stored only on the device (for example, in a TPM chip on the motherboard). The service regularly checks if the browser has the key, and a cookie transferred to another device will not pass this check. DBSC is available for websites starting with Chrome 145, and for Google accounts it will be enabled from April 2026 (Chrome 146 for Windows) and will apply to both Workspace and personal accounts without requiring user action. However, this technology does not protect if the attacker still has access to the device, and it must be implemented separately by each web application.

In Firefox, the cookie database is stored on disk in unencrypted form. This issue has been known since 1999 but remains unresolved. The Total Cookie Protection technology only protects against tracking, not cookie theft.

Recommended Actions in Case of Infection

The order of actions after infection with malware is important. It is recommended to first reinstall the system and only then change passwords. If you change your password on an infected device, the new password will immediately be sent to the attacker.

After changing your password, you must terminate all active sessions individually, since an active cookie allows the attacker to retain access. To do this:

  • Google: myaccount.google.com → “Security” section → “Manage all devices.” Each session is shown separately and can be ended by device.

  • Microsoft: account.microsoft.com → advanced security settings → “Sign out everywhere.” The process may take up to 24 hours; Xbox is not included.

  • Apple: account.apple.com → “Devices” section → select device → “Remove from account.” If someone logs in again on the device, it will reappear.

The correct order: first reinstall the system, then change passwords, and finally end all sessions. Failing to follow this order risks giving new credentials to the attacker.

Passkey: Capabilities and Limitations

Passkey is considered a secure form of authentication, but it only protects the login process, not an already open session. The Pass-the-Passkey attack demonstrates that even this mechanism can be vulnerable.

Current State of Protection

At present, it is impossible to fully prevent cookie theft using only software tools if malware is already present on the device. DBSC technology limits the lifespan of a stolen cookie, allowing it to work only on the device where it was created.

Practical Tips

Until new technologies are widely adopted, users remain responsible for their own security. Do not use pirated software and download programs only from official sources. At the first sign of infection, you should first reinstall the system, then end all sessions, and only after that change your passwords.

#safety#recommendations#browser#two-factor_authentication#угон_сессии#cookie
0 —

Comments (0)

Hot

Qnap has announced new NAS devices for video production

Oct 2, 202610/2/26 · 0 reactions

Tesla opened credit lines worth $30 billion

Oct 2, 202610/2/26 · 0 reactions

Air travel is on the rise, but new regulations are making the market more complicated.

Oct 1, 202610/1/26 · 0 reactions
Recommended
Cloud Computing

Qnap has announced new NAS devices for video production

Qnap has introduced three new NAS systems designed for video production tasks, equipped with USB4 ports for high-speed data transfer. These devices support various connection modes and are intended for use with high-capacity hard drives and SSDs.

Financial Analysis

Tesla opened credit lines worth $30 billion

Tesla has opened credit lines totaling $30 billion to finance major investments amid declining profits and rising capital expenditures. The new agreement expands the company's financial flexibility as it faces increasing pressure on its business.

Transportation Logistics

Air travel is on the rise, but new regulations are making the market more complicated.

Air transportation is becoming an increasingly important part of logistics, especially amid the instability of sea shipping. However, new regulations for preparing air waybills are creating additional challenges and risks for market participants.