{"id":12359,"date":"2024-11-01T06:51:53","date_gmt":"2024-11-01T13:51:53","guid":{"rendered":"https:\/\/legacy.gosecure.ai\/?p=12359"},"modified":"2024-11-12T10:11:25","modified_gmt":"2024-11-12T18:11:25","slug":"threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft","status":"publish","type":"post","link":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/","title":{"rendered":"Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft"},"content":{"rendered":"<p class=\"article-editor-content__paragraph article-editor-content__has-focus\"><img class=\"wp-image-12354 size-medium alignright\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/October-2024-THOTM-300x157.jpg\" alt=\"October 2024 - THOTM\" width=\"300\" height=\"157\" srcset=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-300x157.jpg 300w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-1024x535.jpg 1024w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-768x401.jpg 768w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-1080x564.jpg 1080w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-980x512.jpg 980w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-480x251.jpg 480w, https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM.jpg 1200w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p class=\"article-editor-content__paragraph article-editor-content__has-focus\">In October 2024, GoSecure Threat Hunters have uncovered a sophisticated phishing campaign that utilizes tactics like Attacker-in-the-Middle (AitM) and phishing to compromise user accounts through web session cookie theft. This specific method targets cloud-based file hosting applications such as Dropbox and OneDrive, compromising users by manipulating shared files and redirecting them to malicious sites where both credentials and multi-factor authentication details are stolen.<\/p>\n<p class=\"article-editor-content__paragraph\"><strong>Why This Matters <\/strong><\/p>\n<p class=\"article-editor-content__paragraph\">The theft of web session cookies is a critical threat as it allows attackers to bypass traditional security measures and gain access to sensitive information undetected. These cookies often authenticate personal and financial details, making their theft particularly dangerous. This technique is increasingly used in targeted phishing attacks, making awareness and prevention essential.<\/p>\n<p class=\"article-editor-content__paragraph\"><strong>Detection and Monitoring <\/strong><\/p>\n<p class=\"article-editor-content__paragraph\">GoSecure\u2019s proactive threat hunt in October identified and intercepted phishing attempts using legitimate-looking documents, such as a DocuSign envelope, as a lure to direct victims to malicious sites. Our Threat Hunters have been vigilant in monitoring for signs of this behavior and have established new detection rules that can identify similar threats in real-time.<\/p>\n<p class=\"article-editor-content__paragraph\"><strong>Recommendations <\/strong><\/p>\n<p class=\"article-editor-content__paragraph\">To defend against this type of attack, GoSecure recommends the following steps:<\/p>\n<ul>\n<li class=\"article-editor-content__paragraph\">Enable and enforce multi-factor authentication (MFA) for all cloud services.<\/li>\n<li class=\"article-editor-content__paragraph\">Educate employees about the dangers of phishing and the importance of verifying the authenticity of requests involving sensitive data or credentials.<\/li>\n<li class=\"article-editor-content__paragraph\">Utilize advanced email filtering solutions that can detect and block phishing attempts before they reach end users.<\/li>\n<li class=\"article-editor-content__paragraph\">Review and monitor sign-in logs and file access patterns for unusual activities that could indicate a breach.<\/li>\n<\/ul>\n<p class=\"article-editor-content__paragraph\"><strong>Conclusion<\/strong><\/p>\n<p class=\"article-editor-content__paragraph\">GoSecure remains steadfast in its commitment to detect and mitigate emerging cybersecurity threats. Our MXDR service is designed to provide continuous monitoring and targeted threat detection to protect against complex threats like web session cookie theft. For more detailed information on how we\u2019re actively addressing this issue or to enhance your defenses against such phishing attacks, contact us directly (888)-287-5858 or <a class=\"article-editor-content__link article-editor-content__link\" href=\"mailto:info@gosecure.ai\" rel=\"noopener noreferrer\">info@gosecure.ai<\/a>.<\/p>\n<p class=\"article-editor-content__paragraph\">Stay secure!<\/p>\n<p class=\"article-editor-content__paragraph\">Your GoSecure Threat Hunting Team<\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"article-editor-content__paragraph article-editor-content__has-focus\"><img class=\"wp-image-12354 size-medium alignright\" src=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-300x157.jpg\" alt=\"October 2024 - THOTM\" width=\"300\" height=\"157\" \/><\/p>\n<p>&nbsp;<\/p>\n<p class=\"article-editor-content__paragraph article-editor-content__has-focus\">In October 2024, GoSecure Threat Hunters have uncovered a sophisticated phishing campaign that utilizes tactics like Attacker-in-the-Middle (AitM) and phishing to compromise user accounts through web session cookie theft. This specific method targets cloud-based file hosting applications such as Dropbox and OneDrive, compromising users by manipulating shared files and redirecting them to malicious sites where both credentials and multi-factor authentication details are stolen.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[437,448],"tags":[604,605,606,607,608,520,609,610,611,523,455,612],"class_list":["post-12359","post","type-post","status-publish","format-standard","hentry","category-avis-de-securite","category-phishing-fr","tag-aitm-fr","tag-attacker-in-the-middle-fr","tag-cloud-file-hosting-fr","tag-credentials-theft-fr","tag-cyber-threats-fr","tag-cybersecurity-fr","tag-email-filtering-fr","tag-mfa-fr","tag-multi-factor-authentication-fr","tag-mxdr-fr","tag-phishing-fr","tag-threat-detection-fr"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v23.0 (Yoast SEO v23.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft - GoSecure<\/title>\n<meta name=\"description\" content=\"Discover how GoSecure&#039;s Threat Hunters identified a sophisticated phishing campaign targeting cloud-based file hosting services like Dropbox and OneDrive. Learn about the tactics used, including Attacker-in-the-Middle (AitM) and the theft of web session cookies, and find out how to bolster your defenses with our proactive detection and recommendations.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft\" \/>\n<meta property=\"og:description\" content=\"Discover how GoSecure&#039;s Threat Hunters identified a sophisticated phishing campaign targeting cloud-based file hosting services like Dropbox and OneDrive. Learn about the tactics used, including Attacker-in-the-Middle (AitM) and the theft of web session cookies, and find out how to bolster your defenses with our proactive detection and recommendations.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/\" \/>\n<meta property=\"og:site_name\" content=\"GoSecure\" \/>\n<meta property=\"article:published_time\" content=\"2024-11-01T13:51:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-11-12T18:11:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-300x157.jpg\" \/>\n<meta name=\"author\" content=\"GoSecure\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:site\" content=\"@GoSecure_Inc\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"GoSecure\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/\",\"name\":\"Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft - GoSecure\",\"isPartOf\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/October-2024-THOTM-300x157.jpg\",\"datePublished\":\"2024-11-01T13:51:53+00:00\",\"dateModified\":\"2024-11-12T18:11:25+00:00\",\"author\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\"},\"description\":\"Discover how GoSecure's Threat Hunters identified a sophisticated phishing campaign targeting cloud-based file hosting services like Dropbox and OneDrive. Learn about the tactics used, including Attacker-in-the-Middle (AitM) and the theft of web session cookies, and find out how to bolster your defenses with our proactive detection and recommendations.\",\"breadcrumb\":{\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#primaryimage\",\"url\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/October-2024-THOTM-300x157.jpg\",\"contentUrl\":\"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/October-2024-THOTM-300x157.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/legacy.gosecure.ai\/fr\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#website\",\"url\":\"https:\/\/legacy.gosecure.ai\/fr\/\",\"name\":\"GoSecure\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca\",\"name\":\"GoSecure\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft - GoSecure","description":"Discover how GoSecure's Threat Hunters identified a sophisticated phishing campaign targeting cloud-based file hosting services like Dropbox and OneDrive. Learn about the tactics used, including Attacker-in-the-Middle (AitM) and the theft of web session cookies, and find out how to bolster your defenses with our proactive detection and recommendations.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/","og_locale":"fr_FR","og_type":"article","og_title":"Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft","og_description":"Discover how GoSecure's Threat Hunters identified a sophisticated phishing campaign targeting cloud-based file hosting services like Dropbox and OneDrive. Learn about the tactics used, including Attacker-in-the-Middle (AitM) and the theft of web session cookies, and find out how to bolster your defenses with our proactive detection and recommendations.","og_url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/","og_site_name":"GoSecure","article_published_time":"2024-11-01T13:51:53+00:00","article_modified_time":"2024-11-12T18:11:25+00:00","og_image":[{"url":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/October-2024-THOTM-300x157.jpg"}],"author":"GoSecure","twitter_card":"summary_large_image","twitter_creator":"@GoSecure_Inc","twitter_site":"@GoSecure_Inc","twitter_misc":{"\u00c9crit par":"GoSecure","Dur\u00e9e de lecture estim\u00e9e":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/","url":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/","name":"Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft - GoSecure","isPartOf":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#primaryimage"},"image":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#primaryimage"},"thumbnailUrl":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/October-2024-THOTM-300x157.jpg","datePublished":"2024-11-01T13:51:53+00:00","dateModified":"2024-11-12T18:11:25+00:00","author":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca"},"description":"Discover how GoSecure's Threat Hunters identified a sophisticated phishing campaign targeting cloud-based file hosting services like Dropbox and OneDrive. Learn about the tactics used, including Attacker-in-the-Middle (AitM) and the theft of web session cookies, and find out how to bolster your defenses with our proactive detection and recommendations.","breadcrumb":{"@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#primaryimage","url":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/October-2024-THOTM-300x157.jpg","contentUrl":"https:\/\/legacy.gosecure.ai\/wp-content\/uploads\/\/October-2024-THOTM-300x157.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/legacy.gosecure.ai\/fr\/blog\/2024\/11\/01\/threat-hunt-of-the-month-sophisticated-phishing-campaigns-leveraging-web-session-cookie-theft\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/legacy.gosecure.ai\/fr\/"},{"@type":"ListItem","position":2,"name":"Threat Hunt of the Month: Sophisticated Phishing Campaigns Leveraging Web Session Cookie Theft"}]},{"@type":"WebSite","@id":"https:\/\/legacy.gosecure.ai\/fr\/#website","url":"https:\/\/legacy.gosecure.ai\/fr\/","name":"GoSecure","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/legacy.gosecure.ai\/fr\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/legacy.gosecure.ai\/fr\/#\/schema\/person\/11f4bfed2ab7b748dfc255aa91baedca","name":"GoSecure"}]}},"_links":{"self":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/12359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/comments?post=12359"}],"version-history":[{"count":0,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/posts\/12359\/revisions"}],"wp:attachment":[{"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/media?parent=12359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/categories?post=12359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/legacy.gosecure.ai\/fr\/wp-json\/wp\/v2\/tags?post=12359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}