Web Session Cookie - AML.T0091.001
Definition
Adversaries may use stolen web session cookies to authenticate to AI-enabled applications and supporting services as another user. This technique may bypass some multi-factor authentication controls because the session represented by the cookie has already been authenticated.
Authentication cookies are commonly used by web applications and cloud-based services after a user has authenticated, allowing the user to continue using the service without repeatedly passing credentials. These cookies may remain valid for extended periods of time. After obtaining a cookie through Steal Web Session Cookie, an adversary may import the cookie into a browser or automated client they control and access the corresponding application as the victim while the session remains active.
In attacks on AI systems, web session cookies may grant access to AI chat histories, AI agent control panels, model provider dashboards, customer support systems, retrieval or knowledge management interfaces, or AI DevOps resources. If the stolen cookie belongs to an operator, support agent, developer, or administrator, the adversary may be able to view sensitive conversations, manipulate agent configuration, access private data available through AI tools, or perform actions with the victim account's permissions.
D3FEND Inferred Relationships
There are no artifacts defined on this offensive technique (yet). Please consider contributing an addition to D3FEND.