---
title: "Cookie Thief: Using Reverse Tunnel to Steal Session Cookies and Expose AWS + Salesforce Data"
description: "Cookie Thief: Using Reverse Tunnel to Steal Session Cookies and Expose AWS + Salesforce Data"
image: https://info.varonis.com/hubfs/Attack%20Sims%20EP3%20-%20Cookie%20Thief.png
---

[ Schedule a free demo 

](https://info.varonis.com/en/demo-request?hsLang=en-gb)

[ All Episodes ](https://info.varonis.com/en/attack-sims-series?hsLang=en-gb)

 >

 Episode_03

## Cookie Thief

##### Using Reverse Tunnel to Steal Session Cookies and Expose AWS + Salesforce Data

LIVE EVENT:

 22 February 2023

 11 a.m. GMT

 Reserve your spot

![AttackSims_EmailIllustration_CookieThief-Stealing-AWS-and-SalesforceData](https://info.varonis.com/hubfs/Attack%20Sims/Illustrations/AttackSims_EmailIllustration_CookieThief-Stealing-AWS-and-SalesforceData.png)

Watch Security Architect Thomas Cock compromise just one user but gain persistent access to several SaaS apps.

Thomas will show you how hackers evade common detections, using reverse HTTP tunnel to steal cookies and credentials, and make sensitive AWS, GitHub, and Salesforce data publicly accessible!

Learn how SaaS authentication works, watch the attack unfold in real time, and see how DatAdvantage Cloud spots suspicious activity.

As always, our Attack Sims session will be recorded, so even if you can't make it, go ahead and register so we can send you the replay.

 A high-level overview of how this attack plays out:

- An attacker targets a user through a phishing email to establish a C2 channel
- They then use a homemade script to collect all credentials and cookies from the user’s browser
- The attacker sets up a reverse tunnel to bypass geohopping and network-based alerts
- They bypass MFA using stored cookies and a token from the user
- Afterward, they share out SaaS repositories to be used in the future without detection
- Finally, they set up API access in Salesforce to siphon vital company information

 _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

### Register now

![Thomas Cock](https://info.varonis.com/hubfs/Thomas%20Cock.png)

 Thomas Cock

 Thomas Cock is a Security Architect within the Varonis Incident Response Team, working with customers to investigate and respond to threats.

## Reduce your risk without taking any.

##### Contact us to learn what will be covered in your free data risk assessment.

 Get started

### Get your custom risk assessment

- [ Legal ](https://info.varonis.com/en-gb/webinar/attack-sims-cookie-thief-2023-02-22#)
- |
- [ Trust ](https://info.varonis.com/en-gb/webinar/attack-sims-cookie-thief-2023-02-22#)

- <https://www.facebook.com/VaronisSystems/>
- <https://www.linkedin.com/company/varonis>
- <https://twitter.com/varonis?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor>

- [ Legal ](https://info.varonis.com/en-gb/webinar/attack-sims-cookie-thief-2023-02-22#)
- |
- [ Trust ](https://info.varonis.com/en-gb/webinar/attack-sims-cookie-thief-2023-02-22#)

 © 2026

Varonis