Account Theft: Why Antivirus and 2FA Aren't Enough
Even with active two-factor authentication and antivirus protection, attackers can gain access to accounts by stealing session cookies. This article explains how such attacks work, discusses modern protection methods, and offers practical security recommendations.
Crius
Session Hijacking Mechanism
Even after removing malicious software from a user's device with antivirus tools, spam may continue to be sent from their Google account, and unknown devices may appear in the list of connected devices. Two-factor authentication often remains enabled. This situation is caused by session hijacking—gaining access to an already active user session. In such cases, the attacker does not need to know the password or the second authentication factor; it is enough to obtain a special file—a session cookie—that the browser saves after login to enable automatic authorization during subsequent visits.
How Cookie Theft Happens
Most often, the attack begins when an infostealer program, designed to collect account credentials, infiltrates the device. This can happen through cracked software, fake installers, or malicious attachments. Once installed, the infostealer reads the browser's cookie files. The attacker then imports the stolen cookie into their own browser and gains access to the service without needing to re-authenticate.
According to the Global Threat Intelligence Report for 2025, over 11.1 million devices were infected with infostealers, and 3.3 billion credentials and cloud tokens were stolen. Session cookies are not included in this count.
Features and Limitations of Two-Factor Authentication
Two-factor authentication verifies the user only at login. After successful verification, a cookie is created to confirm authentication. If an attacker obtains this cookie, no further verification is required. Even advanced security programs, such as Google’s Advanced Protection Program, do not change this mechanism. If the user does not log out, the security key may not be requested again.
Measures Taken by Browsers
Since July 2024, Chrome for Windows (starting with version 127) encrypts cookies using App-Bound Encryption and ties the key to the application. However, malware with elevated privileges can bypass this protection, making theft more difficult but not impossible.
A more effective technology is Device Bound Session Credentials (DBSC), where the browser generates a key pair and the private key is stored only on the device (for example, in a TPM chip on the motherboard). The service regularly checks if the browser has the key, and a cookie transferred to another device will not pass this check. DBSC is available for websites starting with Chrome 145, and for Google accounts it will be enabled from April 2026 (Chrome 146 for Windows) and will apply to both Workspace and personal accounts without requiring user action. However, this technology does not protect if the attacker still has access to the device, and it must be implemented separately by each web application.
In Firefox, the cookie database is stored on disk in unencrypted form. This issue has been known since 1999 but remains unresolved. The Total Cookie Protection technology only protects against tracking, not cookie theft.
Recommended Actions in Case of Infection
The order of actions after infection with malware is important. It is recommended to first reinstall the system and only then change passwords. If you change your password on an infected device, the new password will immediately be sent to the attacker.
After changing your password, you must terminate all active sessions individually, since an active cookie allows the attacker to retain access. To do this:
Google: myaccount.google.com → “Security” section → “Manage all devices.” Each session is shown separately and can be ended by device.
Microsoft: account.microsoft.com → advanced security settings → “Sign out everywhere.” The process may take up to 24 hours; Xbox is not included.
Apple: account.apple.com → “Devices” section → select device → “Remove from account.” If someone logs in again on the device, it will reappear.
The correct order: first reinstall the system, then change passwords, and finally end all sessions. Failing to follow this order risks giving new credentials to the attacker.
Passkey: Capabilities and Limitations
Passkey is considered a secure form of authentication, but it only protects the login process, not an already open session. The Pass-the-Passkey attack demonstrates that even this mechanism can be vulnerable.
Current State of Protection
At present, it is impossible to fully prevent cookie theft using only software tools if malware is already present on the device. DBSC technology limits the lifespan of a stolen cookie, allowing it to work only on the device where it was created.
Practical Tips
Until new technologies are widely adopted, users remain responsible for their own security. Do not use pirated software and download programs only from official sources. At the first sign of infection, you should first reinstall the system, then end all sessions, and only after that change your passwords.
