ADVERTISEMENT

Researcher steals cookies from the cookie stealers: here’s what happened next

In a ‘Reverse Uno’ move, security researchers at CyberArk exploited a flaw in the backend of a cookie-stealing malware service, so they stole their cookies to find out more about them.

browser cookies

Image by Cybernews

Ann-Marie Corvin
Ann-Marie Corvin Senior Journalist
January 17, 2026 Updated: January 17, 2026 4 min read
Jurgita Lapienyte justinasv Izabele Pukenaite vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News
Add us as your Preferred Source on Google.

The way in: simple XSS vulnerability

Hijacking YouTube accounts to spread malware

Markerspage-YouTubeTA-r
Markers page from YouTubeTA’s StealC web panel. CyberArk.
ADVERTISEMENT
clickfix-page
Screenshot of likely clickfix page used to install StealC. CyberArk.

Identifying the operator and VPN slip up

MaaS scales, but so do its failures


ADVERTISEMENT